Vulnerability Description
Puma is a Ruby/Rack web server built for parallelism. From 5.5.0 until 7.2.1 and 8.0.2, when PROXY protocol v1 support is enabled, Puma reads incoming bytes into an internal buffer while waiting for CRLF to determine whether a PROXY v1 line is present, allowing an attacker that continuously sends bytes without CRLF to cause unbounded in-process memory growth and additional CPU cost from repeatedly scanning the growing buffer. This issue is fixed in versions 7.2.1 and 8.0.2.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/puma/puma/commit/439c6136d9c2275721b7864db3ee78af7c80889f
- https://github.com/puma/puma/commit/ebe9db3929ab8299d19c8f5b41e8ef4f4b22fa58
- https://github.com/puma/puma/releases/tag/v7.2.1
- https://github.com/puma/puma/releases/tag/v8.0.2
- https://github.com/puma/puma/security/advisories/GHSA-qpgp-93vx-g8v8
FAQ
What is CVE-2026-47736?
CVE-2026-47736 is a vulnerability with a CVSS score of 7.5 (HIGH). Puma is a Ruby/Rack web server built for parallelism. From 5.5.0 until 7.2.1 and 8.0.2, when PROXY protocol v1 support is enabled, Puma reads incoming bytes into an internal buffer while waiting for C...
How severe is CVE-2026-47736?
CVE-2026-47736 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-47736?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.