Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-26803

Опубликовано: 24 фев. 2025
Источник: debian
EPSS Низкий

Описание

The http parser in Phusion Passenger 6.0.21 through 6.0.25 before 6.0.26 allows a denial of service during parsing of a request with an invalid HTTP method.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
passengerfixed6.0.26+ds-1package
passengernot-affectedbookwormpackage
passengernot-affectedbullseyepackage

Примечания

  • https://blog.phusion.nl/2025/02/19/passenger-6-0-26/

  • Introduced with: https://github.com/phusion/passenger/commit/f51fc490472882b236c52d708d605a1961dacb18 (release-6.0.21)

  • Fixed by: https://github.com/phusion/passenger/commit/bb15591646687064ab2d578d5f9660b2a4168017 (release-6.0.26)

EPSS

Процентиль: 69%
0.00605
Низкий

Связанные уязвимости

CVSS3: 5.3
ubuntu
12 месяцев назад

The http parser in Phusion Passenger 6.0.21 through 6.0.25 before 6.0.26 allows a denial of service during parsing of a request with an invalid HTTP method.

CVSS3: 5.3
nvd
12 месяцев назад

The http parser in Phusion Passenger 6.0.21 through 6.0.25 before 6.0.26 allows a denial of service during parsing of a request with an invalid HTTP method.

CVSS3: 5.3
github
12 месяцев назад

Phusion Passenger denial of service

EPSS

Процентиль: 69%
0.00605
Низкий