puma vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-47737Highpuma: Puma PROXY Protocol v1 Accepts Repeated Protocol Headers on Persistent ConnectionsCVE-2026-47736Highpuma: Puma PROXY Protocol v1 Parser Allows Remote Memory Exhaustion CVE-2024-45614Mediumpuma: Puma's header normalization allows for client to clobber proxy set headersCVE-2024-21647Mediumpuma: Puma HTTP Request/Response Smuggling vulnerabilityCVE-2023-40175Criticalpuma: Puma HTTP Request/Response Smuggling vulnerabilityCVE-2022-24790Criticalpuma: Puma vulnerable to HTTP Request SmugglingCVE-2022-23634Highpuma: Puma used with Rails may lead to Information ExposureCVE-2021-41136Lowpuma: Puma with proxy which forwards LF characters as line endings could allow HTTP request smugglingCVE-2021-29509Highpuma: Puma's Keepalive Connections Causing Denial Of ServiceCVE-2020-11077Mediumpuma: HTTP Smuggling via Transfer-Encoding Header in PumaCVE-2020-11076Highpuma: HTTP Smuggling via Transfer-Encoding Header in PumaCVE-2020-5249Mediumpuma: HTTP Response Splitting (Early Hints) in PumaCVE-2020-5247Mediumpuma: HTTP Response Splitting in PumaCVE-2019-16770Mediumpuma: A poorly-behaved client could use keepalive requests to monopolize Puma's reactor and create a denial of service attack

Stop the waste.
Protect your environment with Kodem.