Ruby on Rails Allocation of Resources Without Limits or Throttling Vulnerability - CVE-2019-5419
There is a possible denial of service vulnerability in Action View (Rails) lt5.2.2.1 lt5.1.6.2 lt5.0.7.2 lt4.2.11.1 where specially crafted accept headers can cause action view to consume 100 cpu and make the server unresponsive.