{
  "document": {
    "aggregate_severity": {
      "text": "Important"
    },
    "category": "csaf_security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      },
      {
        "category": "details",
        "text": "CVE-2025-46727: unbounded query parsing in bundled rack; a body of repeated\n  keys was parsed in full, exhausting memory. Capped by rack's new query\n  bytesize and parameter-count limits, which pcsd turns into an HTTP 400\n- CVE-2025-59830: the same unbounded query parse reached through ';' separated\n  query strings, which rack's parameter counter did not count\n- CVE-2025-61770: multipart parsing in bundled rack read the whole request body\n  searching for a boundary that never arrived\n- CVE-2025-61771: multipart parsing in bundled rack retained an unbounded\n  non-file field in memory\n- CVE-2025-61772: multipart mime part headers in bundled rack were read with no\n  size limit\n- CVE-2025-61919: Rack::Request#POST read the entire request body before any\n  limit applied, so a 64 MB body was fully buffered\n- CVE-2024-49761: quadratic regular expression in bundled rexml\n  BaseParser#unnormalize; a long run of zeros in a hex character reference made\n  the parser hang\n- CVE-2024-52804: quadratic cookie unquoting in bundled tornado\n  _unquote_cookie, which rescanned the value from each escape\n- CVE-2025-47287: malformed multipart/form-data in bundled tornado logged a\n  warning per bad part instead of rejecting the request, flooding the log\n- CVE-2026-31958: unbounded part count and part header size in bundled tornado\n  multipart parsing\n- Stop forwarding client HTTP headers from the Tornado front end to the Ruby\n  part of pcsd, which only ever needed the cookie and the content type",
        "title": "Details"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "https://cve.tuxcare.com/els/releases/CLSA-2026:1790243751",
        "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1790243751"
      },
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_os/centos-stream8els/advisories/2026/clsa-2026_1790243751.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-09-24T09:57:22Z",
      "generator": {
        "date": "2026-09-24T09:57:22Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CLSA-2026:1790243751",
      "initial_release_date": "2026-09-24T09:57:22Z",
      "revision_history": [
        {
          "date": "2026-09-24T09:57:22Z",
          "number": "1",
          "summary": "Initial version"
        }
      ],
      "status": "final",
      "version": "1"
    },
    "title": "pcs: Fix of 10 CVEs"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Community Enterprise Operating System 8",
                "product": {
                  "name": "Community Enterprise Operating System 8",
                  "product_id": "CentOS-Stream-8",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:centos:centos:8:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Community Enterprise Operating System"
          }
        ],
        "category": "vendor",
        "name": "Red Hat, Inc."
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "pcs-0:0.10.18-2.el8.tuxcare.els1.x86_64",
                "product": {
                  "name": "pcs-0:0.10.18-2.el8.tuxcare.els1.x86_64",
                  "product_id": "pcs-0:0.10.18-2.el8.tuxcare.els1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/pcs@0.10.18-2.el8.tuxcare.els1?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "pcs-snmp-0:0.10.18-2.el8.tuxcare.els1.x86_64",
                "product": {
                  "name": "pcs-snmp-0:0.10.18-2.el8.tuxcare.els1.x86_64",
                  "product_id": "pcs-snmp-0:0.10.18-2.el8.tuxcare.els1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/pcs-snmp@0.10.18-2.el8.tuxcare.els1?arch=x86_64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          }
        ],
        "category": "vendor",
        "name": "TuxCare"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "pcs-0:0.10.18-2.el8.tuxcare.els1.x86_64 as a component of Community Enterprise Operating System 8",
          "product_id": "CentOS-Stream-8:pcs-0:0.10.18-2.el8.tuxcare.els1.x86_64"
        },
        "product_reference": "pcs-0:0.10.18-2.el8.tuxcare.els1.x86_64",
        "relates_to_product_reference": "CentOS-Stream-8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "pcs-snmp-0:0.10.18-2.el8.tuxcare.els1.x86_64 as a component of Community Enterprise Operating System 8",
          "product_id": "CentOS-Stream-8:pcs-snmp-0:0.10.18-2.el8.tuxcare.els1.x86_64"
        },
        "product_reference": "pcs-snmp-0:0.10.18-2.el8.tuxcare.els1.x86_64",
        "relates_to_product_reference": "CentOS-Stream-8"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2025-61919",
      "cwe": {
        "id": "CWE-400",
        "name": "Uncontrolled Resource Consumption"
      },
      "notes": [
        {
          "category": "description",
          "text": "Rack is a modular Ruby web server interface. Prior to versions 2.2.20, 3.1.18, and 3.2.3, `Rack::Request#POST` reads the entire request body into memory for `Content-Type: application/x-www-form-urlencoded`, calling `rack.input.read(nil)` without enforcing a length or cap. Large request bodies can therefore be buffered completely into process memory before parsing, leading to denial of service (DoS) through memory exhaustion. Users should upgrade to Rack version 2.2.20, 3.1.18, or 3.2.3, anu of which enforces form parameter limits using `query_parser.bytesize_limit`, preventing unbounded reads of `application/x-www-form-urlencoded` bodies. Additionally, enforce strict maximum body size at the proxy or web server layer (e.g., Nginx `client_max_body_size`, Apache `LimitRequestBody`).",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-Stream-8:pcs-0:0.10.18-2.el8.tuxcare.els1.x86_64",
          "CentOS-Stream-8:pcs-snmp-0:0.10.18-2.el8.tuxcare.els1.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2025-61919"
        },
        {
          "category": "external",
          "summary": "https://github.com/rack/rack/commit/4e2c903991a790ee211a3021808ff4fd6fe82881",
          "url": "https://github.com/rack/rack/commit/4e2c903991a790ee211a3021808ff4fd6fe82881"
        },
        {
          "category": "external",
          "summary": "https://github.com/rack/rack/commit/cbd541e8a3d0c5830a3c9a30d3718ce2e124f9db",
          "url": "https://github.com/rack/rack/commit/cbd541e8a3d0c5830a3c9a30d3718ce2e124f9db"
        },
        {
          "category": "external",
          "summary": "https://github.com/rack/rack/commit/e179614c4a653283286f5f046428cbb85f21146f",
          "url": "https://github.com/rack/rack/commit/e179614c4a653283286f5f046428cbb85f21146f"
        },
        {
          "category": "external",
          "summary": "https://github.com/rack/rack/security/advisories/GHSA-6xw4-3v39-52mm",
          "url": "https://github.com/rack/rack/security/advisories/GHSA-6xw4-3v39-52mm"
        }
      ],
      "release_date": "2025-10-10T20:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-24T09:55:53.256165Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els/releases/CLSA-2026:1790243751",
          "product_ids": [
            "CentOS-Stream-8:pcs-0:0.10.18-2.el8.tuxcare.els1.x86_64",
            "CentOS-Stream-8:pcs-snmp-0:0.10.18-2.el8.tuxcare.els1.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1790243751"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2025-61772",
      "cwe": {
        "id": "CWE-400",
        "name": "Uncontrolled Resource Consumption"
      },
      "notes": [
        {
          "category": "description",
          "text": "Rack is a modular Ruby web server interface. In versions prior to 2.2.19, 3.1.17, and 3.2.2, `Rack::Multipart::Parser` can accumulate unbounded data when a multipart part’s header block never terminates with the required blank line (`CRLFCRLF`). The parser keeps appending incoming bytes to memory without a size cap, allowing a remote attacker to exhaust memory and cause a denial of service (DoS). Attackers can send incomplete multipart headers to trigger high memory use, leading to process termination (OOM) or severe slowdown. The effect scales with request size limits and concurrency. All applications handling multipart uploads may be affected. Versions 2.2.19, 3.1.17, and 3.2.2 cap per-part header size (e.g., 64 KiB). As a workaround, restrict maximum request sizes at the proxy or web server layer (e.g., Nginx `client_max_body_size`).",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-Stream-8:pcs-0:0.10.18-2.el8.tuxcare.els1.x86_64",
          "CentOS-Stream-8:pcs-snmp-0:0.10.18-2.el8.tuxcare.els1.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2025-61772"
        },
        {
          "category": "external",
          "summary": "https://github.com/rack/rack/commit/589127f4ac8b5cf11cf88fb0cd116ffed4d2181e",
          "url": "https://github.com/rack/rack/commit/589127f4ac8b5cf11cf88fb0cd116ffed4d2181e"
        },
        {
          "category": "external",
          "summary": "https://github.com/rack/rack/commit/d869fed663b113b95a74ad53e1b5cae6ab31f29e",
          "url": "https://github.com/rack/rack/commit/d869fed663b113b95a74ad53e1b5cae6ab31f29e"
        },
        {
          "category": "external",
          "summary": "https://github.com/rack/rack/commit/e08f78c656c9394d6737c022bde087e0f33336fd",
          "url": "https://github.com/rack/rack/commit/e08f78c656c9394d6737c022bde087e0f33336fd"
        },
        {
          "category": "external",
          "summary": "https://github.com/rack/rack/security/advisories/GHSA-wpv5-97wm-hp9c",
          "url": "https://github.com/rack/rack/security/advisories/GHSA-wpv5-97wm-hp9c"
        }
      ],
      "release_date": "2025-10-07T15:16:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-24T09:55:53.256165Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els/releases/CLSA-2026:1790243751",
          "product_ids": [
            "CentOS-Stream-8:pcs-0:0.10.18-2.el8.tuxcare.els1.x86_64",
            "CentOS-Stream-8:pcs-snmp-0:0.10.18-2.el8.tuxcare.els1.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1790243751"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    },
    {
      "cve": "CVE-2026-31958",
      "cwe": {
        "id": "CWE-400",
        "name": "Uncontrolled Resource Consumption"
      },
      "notes": [
        {
          "category": "description",
          "text": "Tornado is a Python web framework and asynchronous networking library. In versions of Tornado prior to 6.5.5, the only limit on the number of parts in multipart/form-data is the max_body_size setting (default 100MB). Since parsing occurs synchronously on the main thread, this creates the possibility of denial-of-service due to the cost of parsing very large multipart bodies with many parts. This vulnerability is fixed in 6.5.5.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-Stream-8:pcs-0:0.10.18-2.el8.tuxcare.els1.x86_64",
          "CentOS-Stream-8:pcs-snmp-0:0.10.18-2.el8.tuxcare.els1.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2026-31958"
        },
        {
          "category": "external",
          "summary": "https://github.com/tornadoweb/tornado/security/advisories/GHSA-qjxf-f2mg-c6mc",
          "url": "https://github.com/tornadoweb/tornado/security/advisories/GHSA-qjxf-f2mg-c6mc"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2026/04/msg00000.html",
          "url": "https://lists.debian.org/debian-lts-announce/2026/04/msg00000.html"
        }
      ],
      "release_date": "2026-03-11T20:16:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-24T09:55:53.256165Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els/releases/CLSA-2026:1790243751",
          "product_ids": [
            "CentOS-Stream-8:pcs-0:0.10.18-2.el8.tuxcare.els1.x86_64",
            "CentOS-Stream-8:pcs-snmp-0:0.10.18-2.el8.tuxcare.els1.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1790243751"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2025-61771",
      "cwe": {
        "id": "CWE-400",
        "name": "Uncontrolled Resource Consumption"
      },
      "notes": [
        {
          "category": "description",
          "text": "Rack is a modular Ruby web server interface. In versions prior to 2.2.19, 3.1.17, and 3.2.2, ``Rack::Multipart::Parser` stores non-file form fields (parts without a `filename`) entirely in memory as Ruby `String` objects. A single large text field in a multipart/form-data request (hundreds of megabytes or more) can consume equivalent process memory, potentially leading to out-of-memory (OOM) conditions and denial of service (DoS). Attackers can send large non-file fields to trigger excessive memory usage. Impact scales with request size and concurrency, potentially leading to worker crashes or severe garbage-collection overhead. All Rack applications processing multipart form submissions are affected. Versions 2.2.19, 3.1.17, and 3.2.2 enforce a reasonable size cap for non-file fields (e.g., 2 MiB). Workarounds include restricting maximum request body size at the web-server or proxy layer (e.g., Nginx `client_max_body_size`) and validating and rejecting unusually large form fields at the application level.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-Stream-8:pcs-0:0.10.18-2.el8.tuxcare.els1.x86_64",
          "CentOS-Stream-8:pcs-snmp-0:0.10.18-2.el8.tuxcare.els1.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2025-61771"
        },
        {
          "category": "external",
          "summary": "https://github.com/rack/rack/commit/589127f4ac8b5cf11cf88fb0cd116ffed4d2181e",
          "url": "https://github.com/rack/rack/commit/589127f4ac8b5cf11cf88fb0cd116ffed4d2181e"
        },
        {
          "category": "external",
          "summary": "https://github.com/rack/rack/commit/d869fed663b113b95a74ad53e1b5cae6ab31f29e",
          "url": "https://github.com/rack/rack/commit/d869fed663b113b95a74ad53e1b5cae6ab31f29e"
        },
        {
          "category": "external",
          "summary": "https://github.com/rack/rack/commit/e08f78c656c9394d6737c022bde087e0f33336fd",
          "url": "https://github.com/rack/rack/commit/e08f78c656c9394d6737c022bde087e0f33336fd"
        },
        {
          "category": "external",
          "summary": "https://github.com/rack/rack/security/advisories/GHSA-w9pc-fmgc-vxvw",
          "url": "https://github.com/rack/rack/security/advisories/GHSA-w9pc-fmgc-vxvw"
        }
      ],
      "release_date": "2025-10-07T15:16:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-24T09:55:53.256165Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els/releases/CLSA-2026:1790243751",
          "product_ids": [
            "CentOS-Stream-8:pcs-0:0.10.18-2.el8.tuxcare.els1.x86_64",
            "CentOS-Stream-8:pcs-snmp-0:0.10.18-2.el8.tuxcare.els1.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1790243751"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2024-49761",
      "cwe": {
        "id": "CWE-1333",
        "name": "Inefficient Regular Expression Complexity"
      },
      "notes": [
        {
          "category": "description",
          "text": "REXML is an XML toolkit for Ruby. The REXML gem before 3.3.9 has a ReDoS vulnerability when it parses an XML that has many digits between &# and x...; in a hex numeric character reference (&#x...;). This does not happen with Ruby 3.2 or later. Ruby 3.1 is the only affected maintained Ruby. The REXML gem 3.3.9 or later include the patch to fix the vulnerability.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-Stream-8:pcs-0:0.10.18-2.el8.tuxcare.els1.x86_64",
          "CentOS-Stream-8:pcs-snmp-0:0.10.18-2.el8.tuxcare.els1.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2024-49761"
        },
        {
          "category": "external",
          "summary": "https://github.com/ruby/rexml/commit/ce59f2eb1aeb371fe1643414f06618dbe031979f",
          "url": "https://github.com/ruby/rexml/commit/ce59f2eb1aeb371fe1643414f06618dbe031979f"
        },
        {
          "category": "external",
          "summary": "https://github.com/ruby/rexml/security/advisories/GHSA-2rxp-v6pw-ch6m",
          "url": "https://github.com/ruby/rexml/security/advisories/GHSA-2rxp-v6pw-ch6m"
        },
        {
          "category": "external",
          "summary": "https://www.ruby-lang.org/en/news/2024/10/28/redos-rexml-cve-2024-49761",
          "url": "https://www.ruby-lang.org/en/news/2024/10/28/redos-rexml-cve-2024-49761"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2025/01/msg00011.html",
          "url": "https://lists.debian.org/debian-lts-announce/2025/01/msg00011.html"
        },
        {
          "category": "external",
          "summary": "https://security.netapp.com/advisory/ntap-20241227-0004/",
          "url": "https://security.netapp.com/advisory/ntap-20241227-0004/"
        }
      ],
      "release_date": "2024-10-28T15:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-24T09:55:53.256165Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els/releases/CLSA-2026:1790243751",
          "product_ids": [
            "CentOS-Stream-8:pcs-0:0.10.18-2.el8.tuxcare.els1.x86_64",
            "CentOS-Stream-8:pcs-snmp-0:0.10.18-2.el8.tuxcare.els1.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1790243751"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2025-46727",
      "cwe": {
        "id": "CWE-400",
        "name": "Uncontrolled Resource Consumption"
      },
      "notes": [
        {
          "category": "description",
          "text": "Rack is a modular Ruby web server interface. Prior to versions 2.2.14, 3.0.16, and 3.1.14, `Rack::QueryParser` parses query strings and `application/x-www-form-urlencoded` bodies into Ruby data structures without imposing any limit on the number of parameters, allowing attackers to send requests with extremely large numbers of parameters. The vulnerability arises because `Rack::QueryParser` iterates over each `&`-separated key-value pair and adds it to a Hash without enforcing an upper bound on the total number of parameters. This allows an attacker to send a single request containing hundreds of thousands (or more) of parameters, which consumes excessive memory and CPU during parsing. An attacker can trigger denial of service by sending specifically crafted HTTP requests, which can cause memory exhaustion or pin CPU resources, stalling or crashing the Rack server. This results in full service disruption until the affected worker is restarted. Versions 2.2.14, 3.0.16, and 3.1.14 fix the issue. Some other mitigations are available. One may use middleware to enforce a maximum query string size or parameter count, or employ a reverse proxy (such as Nginx) to limit request sizes and reject oversized query strings or bodies. Limiting request body sizes and query string lengths at the web server or CDN level is an effective mitigation.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-Stream-8:pcs-0:0.10.18-2.el8.tuxcare.els1.x86_64",
          "CentOS-Stream-8:pcs-snmp-0:0.10.18-2.el8.tuxcare.els1.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2025-46727"
        },
        {
          "category": "external",
          "summary": "https://github.com/rack/rack/commit/2bb5263b464b65ba4b648996a579dbd180d2b712",
          "url": "https://github.com/rack/rack/commit/2bb5263b464b65ba4b648996a579dbd180d2b712"
        },
        {
          "category": "external",
          "summary": "https://github.com/rack/rack/commit/3f5a4249118d09d199fe480466c8c6717e43b6e3",
          "url": "https://github.com/rack/rack/commit/3f5a4249118d09d199fe480466c8c6717e43b6e3"
        },
        {
          "category": "external",
          "summary": "https://github.com/rack/rack/commit/cd6b70a1f2a1016b73dc906f924869f4902c2d74",
          "url": "https://github.com/rack/rack/commit/cd6b70a1f2a1016b73dc906f924869f4902c2d74"
        },
        {
          "category": "external",
          "summary": "https://github.com/rack/rack/security/advisories/GHSA-gjh7-p2fx-99vx",
          "url": "https://github.com/rack/rack/security/advisories/GHSA-gjh7-p2fx-99vx"
        }
      ],
      "release_date": "2025-05-07T23:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-24T09:55:53.256165Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els/releases/CLSA-2026:1790243751",
          "product_ids": [
            "CentOS-Stream-8:pcs-0:0.10.18-2.el8.tuxcare.els1.x86_64",
            "CentOS-Stream-8:pcs-snmp-0:0.10.18-2.el8.tuxcare.els1.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1790243751"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2025-61770",
      "cwe": {
        "id": "CWE-400",
        "name": "Uncontrolled Resource Consumption"
      },
      "notes": [
        {
          "category": "description",
          "text": "Rack is a modular Ruby web server interface. In versions prior to 2.2.19, 3.1.17, and 3.2.2, `Rack::Multipart::Parser` buffers the entire multipart preamble (bytes before the first boundary) in memory without any size limit. A client can send a large preamble followed by a valid boundary, causing significant memory use and potential process termination due to out-of-memory (OOM) conditions. Remote attackers can trigger large transient memory spikes by including a long preamble in multipart/form-data requests. The impact scales with allowed request sizes and concurrency, potentially causing worker crashes or severe slowdown due to garbage collection. Versions 2.2.19, 3.1.17, and 3.2.2 enforce a preamble size limit (e.g., 16 KiB) or discard preamble data entirely. Workarounds include limiting total request body size at the proxy or web server level and monitoring memory and set per-process limits to prevent OOM conditions.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-Stream-8:pcs-0:0.10.18-2.el8.tuxcare.els1.x86_64",
          "CentOS-Stream-8:pcs-snmp-0:0.10.18-2.el8.tuxcare.els1.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2025-61770"
        },
        {
          "category": "external",
          "summary": "https://github.com/rack/rack/commit/589127f4ac8b5cf11cf88fb0cd116ffed4d2181e",
          "url": "https://github.com/rack/rack/commit/589127f4ac8b5cf11cf88fb0cd116ffed4d2181e"
        },
        {
          "category": "external",
          "summary": "https://github.com/rack/rack/commit/d869fed663b113b95a74ad53e1b5cae6ab31f29e",
          "url": "https://github.com/rack/rack/commit/d869fed663b113b95a74ad53e1b5cae6ab31f29e"
        },
        {
          "category": "external",
          "summary": "https://github.com/rack/rack/commit/e08f78c656c9394d6737c022bde087e0f33336fd",
          "url": "https://github.com/rack/rack/commit/e08f78c656c9394d6737c022bde087e0f33336fd"
        },
        {
          "category": "external",
          "summary": "https://github.com/rack/rack/security/advisories/GHSA-p543-xpfm-54cp",
          "url": "https://github.com/rack/rack/security/advisories/GHSA-p543-xpfm-54cp"
        }
      ],
      "release_date": "2025-10-07T15:16:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-24T09:55:53.256165Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els/releases/CLSA-2026:1790243751",
          "product_ids": [
            "CentOS-Stream-8:pcs-0:0.10.18-2.el8.tuxcare.els1.x86_64",
            "CentOS-Stream-8:pcs-snmp-0:0.10.18-2.el8.tuxcare.els1.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1790243751"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2025-59830",
      "cwe": {
        "id": "CWE-400",
        "name": "Uncontrolled Resource Consumption"
      },
      "notes": [
        {
          "category": "description",
          "text": "Rack is a modular Ruby web server interface. Prior to version 2.2.18, Rack::QueryParser enforces its params_limit only for parameters separated by &, while still splitting on both & and ;. As a result, attackers could use ; separators to bypass the parameter count limit and submit more parameters than intended. Applications or middleware that directly invoke Rack::QueryParser with its default configuration (no explicit delimiter) could be exposed to increased CPU and memory consumption. This can be abused as a limited denial-of-service vector. This issue has been patched in version 2.2.18.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-Stream-8:pcs-0:0.10.18-2.el8.tuxcare.els1.x86_64",
          "CentOS-Stream-8:pcs-snmp-0:0.10.18-2.el8.tuxcare.els1.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2025-59830"
        },
        {
          "category": "external",
          "summary": "https://github.com/rack/rack/commit/54e4ffdd5affebcb0c015cc6ae74635c0831ed71",
          "url": "https://github.com/rack/rack/commit/54e4ffdd5affebcb0c015cc6ae74635c0831ed71"
        },
        {
          "category": "external",
          "summary": "https://github.com/rack/rack/security/advisories/GHSA-625h-95r8-8xpm",
          "url": "https://github.com/rack/rack/security/advisories/GHSA-625h-95r8-8xpm"
        }
      ],
      "release_date": "2025-09-25T15:16:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-24T09:55:53.256165Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els/releases/CLSA-2026:1790243751",
          "product_ids": [
            "CentOS-Stream-8:pcs-0:0.10.18-2.el8.tuxcare.els1.x86_64",
            "CentOS-Stream-8:pcs-snmp-0:0.10.18-2.el8.tuxcare.els1.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1790243751"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2024-52804",
      "cwe": {
        "id": "CWE-400",
        "name": "Uncontrolled Resource Consumption"
      },
      "notes": [
        {
          "category": "description",
          "text": "Tornado is a Python web framework and asynchronous networking library. The algorithm used for parsing HTTP cookies in Tornado versions prior to 6.4.2 sometimes has quadratic complexity, leading to excessive CPU consumption when parsing maliciously-crafted cookie headers. This parsing occurs in the event loop thread and may block the processing of other requests. Version 6.4.2 fixes the issue.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-Stream-8:pcs-0:0.10.18-2.el8.tuxcare.els1.x86_64",
          "CentOS-Stream-8:pcs-snmp-0:0.10.18-2.el8.tuxcare.els1.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2024-52804"
        },
        {
          "category": "external",
          "summary": "https://github.com/advisories/GHSA-7pwv-g7hj-39pr",
          "url": "https://github.com/advisories/GHSA-7pwv-g7hj-39pr"
        },
        {
          "category": "external",
          "summary": "https://github.com/tornadoweb/tornado/commit/d5ba4a1695fbf7c6a3e54313262639b198291533",
          "url": "https://github.com/tornadoweb/tornado/commit/d5ba4a1695fbf7c6a3e54313262639b198291533"
        },
        {
          "category": "external",
          "summary": "https://github.com/tornadoweb/tornado/security/advisories/GHSA-8w49-h785-mj3c",
          "url": "https://github.com/tornadoweb/tornado/security/advisories/GHSA-8w49-h785-mj3c"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2025/01/msg00000.html",
          "url": "https://lists.debian.org/debian-lts-announce/2025/01/msg00000.html"
        }
      ],
      "release_date": "2024-11-22T16:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-24T09:55:53.256165Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els/releases/CLSA-2026:1790243751",
          "product_ids": [
            "CentOS-Stream-8:pcs-0:0.10.18-2.el8.tuxcare.els1.x86_64",
            "CentOS-Stream-8:pcs-snmp-0:0.10.18-2.el8.tuxcare.els1.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1790243751"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2025-47287",
      "cwe": {
        "id": "CWE-770",
        "name": "Allocation of Resources Without Limits or Throttling"
      },
      "notes": [
        {
          "category": "description",
          "text": "Tornado is a Python web framework and asynchronous networking library. When Tornado's ``multipart/form-data`` parser encounters certain errors, it logs a warning but continues trying to parse the remainder of the data. This allows remote attackers to generate an extremely high volume of logs, constituting a DoS attack. This DoS is compounded by the fact that the logging subsystem is synchronous. All versions of Tornado prior to 6.5.0 are affected. The vulnerable parser is enabled by default. Upgrade to Tornado version 6.50 to receive a patch. As a workaround, risk can be mitigated by blocking `Content-Type: multipart/form-data` in a proxy.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-Stream-8:pcs-0:0.10.18-2.el8.tuxcare.els1.x86_64",
          "CentOS-Stream-8:pcs-snmp-0:0.10.18-2.el8.tuxcare.els1.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2025-47287"
        },
        {
          "category": "external",
          "summary": "https://github.com/tornadoweb/tornado/commit/b39b892bf78fe8fea01dd45199aa88307e7162f3",
          "url": "https://github.com/tornadoweb/tornado/commit/b39b892bf78fe8fea01dd45199aa88307e7162f3"
        },
        {
          "category": "external",
          "summary": "https://github.com/tornadoweb/tornado/security/advisories/GHSA-7cx3-6m66-7c5m",
          "url": "https://github.com/tornadoweb/tornado/security/advisories/GHSA-7cx3-6m66-7c5m"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2025/05/msg00038.html",
          "url": "https://lists.debian.org/debian-lts-announce/2025/05/msg00038.html"
        }
      ],
      "release_date": "2025-05-15T22:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-24T09:55:53.256165Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els/releases/CLSA-2026:1790243751",
          "product_ids": [
            "CentOS-Stream-8:pcs-0:0.10.18-2.el8.tuxcare.els1.x86_64",
            "CentOS-Stream-8:pcs-snmp-0:0.10.18-2.el8.tuxcare.els1.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1790243751"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    }
  ]
}