Loading...
Loading...
lib/rack/multipart.rb in Rack before 1.1.4, 1.2.x before 1.2.6, 1.3.x before 1.3.7, and 1.4.x before 1.4.2 uses an incorrect regular expression, which allows remote attackers to cause a denial of service (infinite loop) via a crafted Content-Disposion header.
March 1, 2013
April 29, 2026
See which npm, PyPI, Go, and Maven packages are affected by CVE-2012-6109
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.