← Vulnerability feed

Vulnerability record · CVE-2018-16470 · published 13 November 2018

CVE-2018-16470: Rack project rack uncontrolled resource consumption vulnerability

Rack Project · Rack

There is a possible DoS vulnerability in the multipart parser in Rack before 2.0.6. Specially crafted requests can cause the multipart parser to enter a pathological state, causing the parser to use CPU resources disproportionate to the request size.

7.5 CVSS 3.0 High EPSS 2.0% · top 19.7% CWE-400 · Uncontrolled resource consumption
7.5CVSS 3.0 base score, v2 5.0
2.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

There is a possible DoS vulnerability in the multipart parser in Rack before 2.0.6. Specially crafted requests can cause the multipart parser to enter a pathological state, causing the parser to use CPU resources disproportionate to the request size.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-16470 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2022-30123Rack project rack vulnerabilityA sequence injection vulnerability exists in Rack <2.0.9.1, <2.1.4.1 and <2.2.3.1 which could allow is a possible shell escape in the Lint and Common…EPSS 1.9%8.6CVE-2020-8161Rack project rack path traversal vulnerabilityA directory traversal vulnerability exists in rack < 2.2.0 that allows an attacker perform directory traversal vulnerability in the Rack::Directory a…EPSS 3.4%7.5CVE-2022-30122Rack project rack uncontrolled resource consumption vulnerabilityA possible denial of service vulnerability exists in Rack <2.0.9.1, <2.1.4.1 and <2.2.3.1 in the multipart parsing component of Rack.EPSS 2.2%7.5CVE-2020-8184Rack project rack improper input validation vulnerabilityA reliance on cookies without validation/integrity check security vulnerability exists in rack < 2.2.3, rack < 2.1.4 that makes it is possible for an…EPSS 2.9%6.1CVE-2018-16471Rack project rack cross-site scripting vulnerabilityThere is a possible XSS vulnerability in Rack before 2.0.6 and 1.6.11. Carefully crafted requests can impact the data returned by the `scheme` method…EPSS 1.9%5.1CVE-2013-0263Rack project rack vulnerabilityRack::Session::Cookie in Rack 1.5.x before 1.5.2, 1.4.x before 1.4.5, 1.3.x before 1.3.10, 1.2.x before 1.2.8, and 1.1.x before 1.1.6 allows remote a…EPSS 5.4%5.0CVE-2015-3225Rack project rack vulnerabilitylib/rack/utils.rb in Rack before 1.5.4 and 1.6.x before 1.6.2, as used with Ruby on Rails 3.x and 4.x and other products, allows remote attackers to …EPSS 8.0%5.0CVE-2013-0183Rack project rack memory buffer overflow vulnerabilitymultipart/parser.rb in Rack 1.3.x before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to cause a denial of service (memory consumption and ou…EPSS 3.8%

Source: NIST National Vulnerability Database (record CVE-2018-16470), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.