Denial of Service Vulnerability in Middleware by RS
CVE-2025-47908

7.5HIGH

Key Information:

Vendor
CVE Published:
6 August 2025

What is CVE-2025-47908?

A vulnerability in RS Middleware allows attackers to exploit a flaw in the handling of malicious preflight requests. When an Access-Control-Request-Headers (ACRH) header with excessive commas is processed, it leads to excessive heap allocations. This behavior can be manipulated to generate significant load on the server, resulting in potential service disruptions and unavailability for legitimate users.

Affected Version(s)

github.com/rs/cors 1.9.0 < 1.11.0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

@jub0bs
.