Launch Week Day 1: Announcing Security Design Review
MEDIUM 5.9 RubyGems

Puma HTTP Request/Response Smuggling vulnerability

GHSA-c2f4-cvqm-65w2 · CVE-2024-21647

Published · Modified

Description

Impact

Prior to versions 6.4.2 and 5.6.8, puma exhibited dangerous behavior when parsing chunked transfer encoding bodies.

Fixed versions limit the size of chunk extensions. Without this limit, an attacker could cause unbounded resource (CPU, network bandwidth) consumption.

Patches

The vulnerability has been fixed in 6.4.2 and 5.6.8.

Workarounds

No known workarounds.

References

Ready to move

Start Securing

Free, no credit card | First findings in minutes