GHSA-5r2p-j47h-mhpg · Severity: medium · Ecosystem: rubygems — Rack vulnerable to Cross-site Scripting
There is a possible XSS vulnerability in Rack before 2.0.6 and 1.6.11. Carefully crafted requests can impact the data returned by the `scheme` method on `Rack::Request`. Applications that expect the scheme to be limited to 'http' or 'https' and do not escape the return value could be vulnerable to an XSS attack. Note that applications using the normal escaping mechanisms provided by Rails may not impacted, but applications that bypass the escaping mechanisms, or do not use them may be vulnerable.
Conclusion & alert: CVE-2018-16471 is rated Moderate Risk (51.9/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 1.82%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.83% | 1.82% | +0.99% |
| 2 | 2026-04-20 | 0.30% | 0.83% | +0.53% |
| 3 | 2026-03-26 | — | 0.30% | — |
Full EPSS history (51 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 6.1 | 3.0 | MEDIUM |
|
2.8 | 2.7 | [email protected] |
| 4.3 | 2.0 | MEDIUM |
|
8.6 | 2.9 | [email protected] |
GHSA-5r2p-j47h-mhpg · Severity: medium · Ecosystem: rubygems — Rack vulnerable to Cross-site Scripting
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
not yet assigned | CVE-2018-16471 not yet assigned priority: Debian including 1 source packages (ruby-rack), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2018-16471 |
redhat
|
medium | — | https://access.redhat.com/security/cve/CVE-2018-16471 |
suse
|
medium | — | https://www.suse.com/security/cve/CVE-2018-16471/ |
ubuntu
|
medium | CVE-2018-16471 medium priority: Ubuntu including 1 source packages (ruby-rack), 12 status rows across 12 suites (bionic, cosmic, disco, eoan, focal, groovy, hirsute, impish, jammy, trusty, upstream, xenial): not-affected 7, released 4, ignored 1. | https://ubuntu.com/security/CVE-2018-16471 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| rack_project | rack | >= 1.6.0, < 1.6.11 | cpe:2.3:a:rack_project:rack:*:*:*:*:*:*:*:* |
| rack_project | rack | >= 2.0.0, < 2.0.6 | cpe:2.3:a:rack_project:rack:*:*:*:*:*:*:*:* |
| debian | debian_linux | 8.0 | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* |