CVE-2025-25184: Possible Log Injection in Rack::CommonLogger
(updated )
Rack::CommonLogger
can be exploited by crafting input that includes newline characters to manipulate log entries. The supplied proof-of-concept demonstrates injecting malicious content into logs.
References
- github.com/advisories/GHSA-7g2v-jj9q-g3rg
- github.com/rack/rack
- github.com/rack/rack/commit/074ae244430cda05c27ca91cda699709cfb3ad8e
- github.com/rack/rack/security/advisories/GHSA-7g2v-jj9q-g3rg
- github.com/rubysec/ruby-advisory-db/blob/master/gems/rack/CVE-2025-25184.yml
- nvd.nist.gov/vuln/detail/CVE-2025-25184
Detect and mitigate CVE-2025-25184 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →