Vulnerability Description
The http parser in Phusion Passenger 6.0.21 through 6.0.25 before 6.0.26 allows a denial of service during parsing of a request with an invalid HTTP method.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Phusion | Passenger | >= 6.0.21, < 6.0.26 |
Related Weaknesses (CWE)
References
- https://blog.phusion.nl/2025/02/19/passenger-6-0-26/Vendor Advisory
- https://github.com/phusion/passenger/commit/bb15591646687064ab2d578d5f9660b2a416Patch
- https://github.com/phusion/passenger/compare/release-6.0.25...release-6.0.26Patch
- https://github.com/phusion/passenger/releases/tag/release-6.0.26Patch
- https://www.phusionpassenger.com/supportProduct
FAQ
What is CVE-2025-26803?
CVE-2025-26803 is a vulnerability with a CVSS score of 5.3 (MEDIUM). The http parser in Phusion Passenger 6.0.21 through 6.0.25 before 6.0.26 allows a denial of service during parsing of a request with an invalid HTTP method.
How severe is CVE-2025-26803?
CVE-2025-26803 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-26803?
Check the references section above for vendor advisories and patch information. Affected products include: Phusion Passenger.