CVE-2022-44571
Ruby vulnerability analysis and mitigation

Overview

CVE-2022-44571 is a vulnerability discovered in Rack, a modular Ruby webserver interface, affecting versions 2.0.0 and later. The vulnerability involves a denial of service (DoS) issue in the Content-Disposition header parsing component. This vulnerability was disclosed on January 17, 2023, and has been assigned a CVSS score of 7.5 (HIGH) (NetApp Security).

Technical details

The vulnerability is caused by a regular expression denial of service (ReDoS) in the Content-Disposition header parsing component. When processing multipart POST requests, carefully crafted input can cause the parsing operation to take an unexpected amount of time. This header is typically used in multipart parsing, affecting virtually all Rails applications that parse multipart posts using Rack (Ruby Rails Discussion).

Impact

Successful exploitation of this vulnerability could lead to a denial of service condition. Any applications that parse multipart posts using Rack, which includes most Rails applications, are potentially impacted. An attacker could cause the application to consume excessive resources, potentially making the service unavailable (Ubuntu Security).

Mitigation and workarounds

Fixed versions have been released: 2.0.9.2, 2.1.4.2, 2.2.6.1, and 3.0.4.1. There are no feasible workarounds for this issue, and users are advised to upgrade to the patched versions. For users unable to upgrade immediately, patches have been provided for the supported release series in git-am format (Ruby Rails Discussion).

Additional resources


SourceThis report was generated using AI

Related Ruby vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-66568CRITICAL9.3
  • RubyRuby
  • ruby-saml
NoYesDec 09, 2025
CVE-2025-66567CRITICAL9.3
  • RubyRuby
  • ruby-saml
NoYesDec 09, 2025
GHSA-4249-gjr8-jpq3HIGH8.7
  • RubyRuby
  • prosemirror_to_html
NoYesNov 13, 2025
CVE-2025-64501HIGH7.6
  • RubyRuby
  • prosemirror_to_html
NoYesNov 10, 2025
CVE-2025-61594MEDIUMN/A
  • RubyRuby
  • ruby-default-gems
NoYesDec 11, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management