📦 Puma

by Puma

🔍 What is Puma?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2022-24790

CRITICAL CVSS 9.1 Mar 30, 2022

CVE-2022-24790 is an HTTP request smuggling vulnerability in Puma HTTP server that allows attackers to bypass front-end proxies and send malicious requests directly to the application. This affects Ru...

CVE-2023-40175

HIGH CVSS 7.3 Aug 18, 2023

This CVE describes an HTTP request smuggling vulnerability in Puma web server that allows attackers to bypass security controls by sending specially crafted HTTP requests. The vulnerability affects Pu...

CVE-2024-45614

MEDIUM CVSS 5.4 Sep 19, 2024

This vulnerability in Puma web server allows clients to override proxy-set headers like X-Forwarded-For by sending underscore versions (X-Forwarded_For). This affects any users relying on proxy header...