Description
An issue in Puma v.5.0.0 and before v.8.0.3 allows an attacker to execute arbitrary code via the ext/puma_http11/http11_parser.rl file
Published: 2026-09-10
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Patch Immediately
AI Analysis

Impact

The vulnerability resides in Puma’s HTTP/1.1 parser within ext/puma_http11/http11_parser.rl. An attacker can forge a specially crafted request that exploits the parser’s logic, leading to arbitrary code execution on the host running Puma. This gives an attacker full control over the server process and can be used to launch additional attacks or exfiltrate data.

Affected Systems

All installations of Puma Web Server with versions from 5.0.0 up to but not including 8.0.3 (i.e., 8.0.2 and earlier) are affected. The vulnerability is independent of the operating system and exists wherever Puma accepts HTTP traffic.

Risk and Exploitability

The flaw permits remote code execution over the network; the CVSS score of 9.1 marks it as critical, while the EPSS score of <1% indicates wild. The vulnerability is not listed in the CISA KEV catalog. An attacker can exploit the vulnerability by sending a crafted HTTP/1.1 request to Puma, without any credentials, leveraging the parser flaw in ext/puma_http11/http11_parser.rl. The attack vector is purely network based, targeting the port Puma listens on.

Generated by OpenCVE AI on September 21, 2026 at 05:34 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Puma to a version that is not vulnerable (i.e., 8.0.3 or later HTTP parser does not perform unsafe dynamic code execution).
  • In the interim, restrict external access to the Puma HTTP port using firewalls or reverse proxies, limiting connections to trusted HTTP parser errors and monitoring these logs for patterns indicating malicious request activity.
  • Regularly monitor Puma logs for anomalous requests and trigger alerts for potential exploitation attempts.

Generated by OpenCVE AI on September 21, 2026 at 05:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Mon, 21 Sep 2026 06:00:00 +0000

Type Values Removed Values Added
Title Puma Web Server HTTP/1.1 Parser Arbitrary Code Execution Vulnerability

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-444
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
First Time appeared Puma
Puma puma
Vendors & Products Puma
Puma puma

Fri, 11 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via Unsafe HTTP/1.1 Parser in Puma

Fri, 11 Sep 2026 05:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-94

Fri, 11 Sep 2026 02:15:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via Unsafe HTTP/1.1 Parser in Puma
Weaknesses CWE-94

Thu, 10 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Title Arbitrary code execution via HTTP/1.1 parser in Puma
Weaknesses CWE-94

Thu, 10 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Title Arbitrary code execution via HTTP/1.1 parser in Puma
Weaknesses CWE-94

Thu, 10 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description An issue in Puma v.5.0.0 and before v.8.0.3 allows an attacker to execute arbitrary code via the ext/puma_http11/http11_parser.rl file
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-14T18:14:32.955Z

Reserved: 2026-07-30T00:00:00.000Z

Link: CVE-2026-68006

cve-icon Vulnrichment

Updated: 2026-09-14T18:14:06.791Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-10T18:18:04.960

Modified: 2026-09-14T19:17:39.727

Link: CVE-2026-68006

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T05:45:10Z

Weaknesses
  • CWE-444

    Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')