Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-47737

Опубликовано: 14 июл. 2026
Источник: redhat
CVSS3: 7.5

Описание

Puma is a Ruby/Rack web server built for parallelism. From 5.5.0 until 7.2.1 and 8.0.2, Puma is vulnerable to source IP spoofing when set_remote_address proxy_protocol: :v1 is enabled and persistent connections are used because Puma incorrectly re-parses PROXY protocol headers after each keep-alive request on the same connection, allowing an attacker to inject a second PROXY header and overwrite REMOTE_ADDR. This issue is fixed in versions 7.2.1 and 8.0.2.

A flaw was found in Puma, a Ruby/Rack web server. When set_remote_address proxy_protocol: :v1 is enabled and persistent connections are used, Puma incorrectly re-parses PROXY protocol headers after each keep-alive request on the same connection. This allows a remote attacker to inject a second PROXY header, leading to source IP (Internet Protocol) spoofing and potentially impacting security logging or access control decisions.

Отчет

This flaw only affects Puma deployments that explicitly enable set_remote_address proxy_protocol: :v1 together with persistent (keep-alive) connections to the proxy. This is not Puma default configuration.

Меры по смягчению последствий

Upgrade puma to 7.2.1 or 8.0.2 (or later). If an immediate upgrade is not possible, remove the set_remote_address proxy_protocol: :v1 configuration, or disable persistent connections (enable_keep_alives false), to prevent PROXY protocol v1 header re-parsing on the same connection.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat 3scale API Management Platform 23scale-amp21/backendNot affected
Red Hat 3scale API Management Platform 23scale-amp21/zyncNot affected
Red Hat 3scale API Management Platform 23scale-amp22/backendNot affected
Red Hat 3scale API Management Platform 23scale-amp22/zyncNot affected
Red Hat 3scale API Management Platform 23scale-amp2/backend-rhel8Not affected
Red Hat 3scale API Management Platform 23scale-amp2/zync-rhel8Not affected
Red Hat 3scale API Management Platform 23scale-amp2/zync-rhel9Not affected
Red Hat Enterprise Linux 10pcsNot affected
Red Hat Enterprise Linux 8pcsNot affected
Red Hat Enterprise Linux 9pcsNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-358
https://bugzilla.redhat.com/show_bug.cgi?id=2500584puma: Puma: Source IP spoofing via PROXY protocol header re-parsing

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
23 дня назад

Puma is a Ruby/Rack web server built for parallelism. From 5.5.0 until 7.2.1 and 8.0.2, Puma is vulnerable to source IP spoofing when set_remote_address proxy_protocol: :v1 is enabled and persistent connections are used because Puma incorrectly re-parses PROXY protocol headers after each keep-alive request on the same connection, allowing an attacker to inject a second PROXY header and overwrite REMOTE_ADDR. This issue is fixed in versions 7.2.1 and 8.0.2.

CVSS3: 7.5
nvd
23 дня назад

Puma is a Ruby/Rack web server built for parallelism. From 5.5.0 until 7.2.1 and 8.0.2, Puma is vulnerable to source IP spoofing when set_remote_address proxy_protocol: :v1 is enabled and persistent connections are used because Puma incorrectly re-parses PROXY protocol headers after each keep-alive request on the same connection, allowing an attacker to inject a second PROXY header and overwrite REMOTE_ADDR. This issue is fixed in versions 7.2.1 and 8.0.2.

CVSS3: 7.5
debian
23 дня назад

Puma is a Ruby/Rack web server built for parallelism. From 5.5.0 until ...

CVSS3: 7.5
github
около 2 месяцев назад

Puma PROXY Protocol v1 Accepts Repeated Protocol Headers on Persistent Connections

7.5 High

CVSS3