Skip to content

Add CVSS 3.1 severity for GHSA-xj5v-6v4g-jfw6#6870

Open
sunnypatell wants to merge 1 commit intogithub:sunnypatell/advisory-improvement-6870from
sunnypatell:cvss-GHSA-xj5v-6v4g-jfw6
Open

Add CVSS 3.1 severity for GHSA-xj5v-6v4g-jfw6#6870
sunnypatell wants to merge 1 commit intogithub:sunnypatell/advisory-improvement-6870from
sunnypatell:cvss-GHSA-xj5v-6v4g-jfw6

Conversation

@sunnypatell
Copy link

Changes

Added CVSS 3.1 scoring to GHSA-xj5v-6v4g-jfw6 (Rack DoS via crafted Range header).

  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H (7.5 High)

CVSS justification

  • AV:N - exploitable via HTTP requests to any Rack-based application
  • AC:L/PR:N/UI:N - unauthenticated attacker can send a crafted Range header with no special setup
  • A:H - malicious Range headers cause unexpectedly large responses, exhausting server memory/bandwidth

References

Copilot AI review requested due to automatic review settings February 13, 2026 20:56
@github-actions github-actions bot changed the base branch from main to sunnypatell/advisory-improvement-6870 February 13, 2026 20:58
Copy link

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot encountered an error and was unable to review this pull request. You can try again by re-requesting a review.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant