Skip to content

Commit 30b8e39

Browse files
committed
Fixing ReDoS in header parsing
Thanks svalkanov [CVE-2024-26146]
1 parent 9996d40 commit 30b8e39

File tree

1 file changed

+2
-2
lines changed

1 file changed

+2
-2
lines changed

lib/rack/utils.rb

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -140,8 +140,8 @@ def build_nested_query(value, prefix = nil)
140140
module_function :build_nested_query
141141

142142
def q_values(q_value_header)
143-
q_value_header.to_s.split(/\s*,\s*/).map do |part|
144-
value, parameters = part.split(/\s*;\s*/, 2)
143+
q_value_header.to_s.split(',').map do |part|
144+
value, parameters = part.split(';', 2).map(&:strip)
145145
quality = 1.0
146146
if md = /\Aq=([\d.]+)/.match(parameters)
147147
quality = md[1].to_f

0 commit comments

Comments
 (0)