CVE-2025-27219
ADVISORY - githubSummary
There is a possibility for DoS by in the cgi gem. This vulnerability has been assigned the CVE identifier CVE-2025-27219. We recommend upgrading the cgi gem.
Details
CGI::Cookie.parse took super-linear time to parse a cookie string in some cases. Feeding a maliciously crafted cookie string into the method could lead to a Denial of Service.
Please update CGI gem to version 0.3.5.1, 0.3.7, 0.4.2 or later.
Affected versions
cgi gem versions <= 0.3.5, 0.3.6, 0.4.0 and 0.4.1.
Credits
Thanks to lio346 for discovering this issue. Also thanks to mame for fixing this vulnerability.
Common Weakness Enumeration (CWE)
Allocation of Resources Without Limits or Throttling
Allocation of Resources Without Limits or Throttling
NIST
3.9
CVSS SCORE
5.8mediumGitHub
CVSS SCORE
6.3mediumAlpine
-
Debian
-
Ubuntu
3.9
CVSS SCORE
7.5mediumAlma
-
CVSS SCORE
N/AmediumAlma
-
CVSS SCORE
N/AmediumAmazon
-
CVSS SCORE
N/AmediumRed Hat
3.9
CVSS SCORE
5.8mediumRocky
-
CVSS SCORE
N/AlowRocky
-
CVSS SCORE
N/AlowRocky
-
CVSS SCORE
N/AlowRocky
-
CVSS SCORE
N/AlowRocky
-
CVSS SCORE
N/AlowRocky
-
CVSS SCORE
N/AlowOracle
-
CVSS SCORE
N/AmediumOracle
-
CVSS SCORE
N/AmediumOracle
-
CVSS SCORE
N/AmediumOracle
-
CVSS SCORE
N/AmediumOracle
-
CVSS SCORE
N/AmediumOracle
-
CVSS SCORE
N/AmediumChainguard
CGA-375j-4vg6-8f37
-
Chainguard
CGA-53pc-p8wf-wrq3
-
Chainguard
CGA-8jwh-f9mm-2jwp
-
Chainguard
CGA-hcpq-57j9-pjwg
-
Chainguard
CGA-jq24-rxcc-x8p8
-
Photon
CVE-2025-27219
-
CVSS SCORE
7.5highminimos
MINI-39rw-4457-p7w3
-
minimos
MINI-5gxg-72f4-6jwp
-
minimos
MINI-74xg-j2pp-528j
-
minimos
MINI-8rf2-q5jm-5h55
-
minimos
MINI-95rv-j253-f8mg
-
minimos
MINI-c3jm-49p9-5m72
-
minimos
MINI-f8r8-846q-v9p9
-
minimos
MINI-gcvh-xjcv-w237
-
minimos
MINI-jpfc-wfmm-5w9j
-
minimos
MINI-p94m-62w2-jpfp
-
minimos
MINI-pwmx-3r6c-9m64
-
minimos
MINI-wc4p-57pq-43p9
-
minimos
MINI-xff6-mfj2-mh8h
-