CVE-2023-27530: Debian Linux

High severity, CVSS 7.5. EPSS: 1.8% chance of exploitation in the next 30 days.

A DoS vulnerability exists in Rack <v3.0.4.2, <v2.2.6.3, <v2.1.4.3 and <v2.0.9.3 within in the Multipart MIME parsing code in which could allow an attacker to craft requests that can be abuse to cause multipart parsing to take longer than expected.

Affected products

  • Debian Debian Linux: version 10.0 only; version 11.0 only
  • Rack Rack: before 2.0.9.3 (fixed in 2.0.9.3); from 2.1.0, before 2.1.4.3 (fixed in 2.1.4.3); from 2.2.0, before 2.2.6.3 (fixed in 2.2.6.3); from 3.0.0, before 3.0.4.2 (fixed in 3.0.4.2)

Published 2023-03-10. Last modified 2026-06-17.