Vulnerabilidades en puma
14 resultadosAnálisis Vexday
A Puma apresenta um perfil de risco moderado com 14 vulnerabilidades catalogadas, embora nenhuma esteja atualmente sob exploração ativa. Apenas 1 vulnerabilidade crítica foi identificada, e 2 foram divulgadas nos últimos 90 dias, indicando um ritmo controlado de descobertas. A fraqueza dominante (CWE-444) aponta para problemas relacionados a validação de entrada HTTP, sugerindo foco em hardening de camadas de parsing e validação de requisições.
CVE-2020-11076HIGHHTTP Smuggling via Transfer-Encoding Header in PumaEPSS 4.1%CVE-2020-11077MEDIUMHTTP Smuggling via Transfer-Encoding Header in PumaEPSS 2.8%CVE-2020-5247MEDIUMHTTP Response Splitting in PumaEPSS 2.5%CVE-2022-24790CRITICALHTTP Request Smuggling in pumaEPSS 2.1%CVE-2022-23634HIGHInformation Exposure when using Puma with RailsEPSS 2.1%CVE-2019-16770MEDIUMPotential DOS attack in PumaEPSS 2.0%CVE-2021-29509HIGHKeepalive Connections Causing Denial Of Service in pumaEPSS 1.6%CVE-2020-5249MEDIUMHTTP Response Splitting (Early Hints) in PumaEPSS 1.6%CVE-2021-41136LOWInconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') in pumaEPSS 1.2%CVE-2024-21647MEDIUMHTTP Request/Response Smuggling in pumaEPSS 1.0%CVE-2023-40175HIGHInconsistent Interpretation of HTTP Requests in pumaEPSS 0.7%CVE-2024-45614MEDIUMHeader normalization allows for client to clobber proxy set headers in PumaEPSS 0.6%CVE-2026-47736HIGHPuma PROXY Protocol v1 Parser Allows Remote Memory ExhaustionEPSS 0.3%CVE-2026-47737HIGHPuma PROXY Protocol v1 Accepts Repeated Protocol Headers on Persistent ConnectionsEPSS 0.2%