GHSA-68xg-gqqm-vgj8

    Dashboard / Vulnerabilities / GHSA-68xg-gqqm-vgj8

    GHSA-68xg-gqqm-vgj8

    Published: 18 Aug 2023Last Modified: 10 Sept 2026

    Summary: Puma HTTP Request/Response Smuggling vulnerability

    Details: ### Impact Prior to version 6.3.1, puma exhibited incorrect behavior when parsing chunked transfer encoding bodies and zero-length Content-Length headers in a way that allowed HTTP request smuggling. The following vulnerabilities are addressed by this advisory: * Incorrect parsing of trailing fields in chunked transfer encoding bodies * Parsing of blank/zero-length Content-Length headers ### Patches The vulnerability has been fixed in 6.3.1 and 5.6.7. ### Workarounds No known workarounds. ### References [HTTP Request Smuggling](https://portswigger.net/web-security/request-smuggling) ### For more information If you have any questions or comments about this advisory: Open an issue in [Puma](https://github.com/puma/puma) See our [security policy](https://github.com/puma/puma/security/policy)

    Affected packages

    Package

    Name: puma

    Purl: pkg:gem/puma

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -5.6.7

    Affected versions

    0.8.0
    0.8.1
    0.8.2

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-68xg-gqqm-vgj8 | CVE-DB