VDB
KO
HIGH 7.5

GHSA-x7jg-6pwg-fx5h

HTTP Smuggling via Transfer-Encoding Header in Puma

Details

### Impact

By using an invalid transfer-encoding header, an attacker could [smuggle an HTTP response.](https://portswigger.net/web-security/request-smuggling)

Originally reported by @ZeddYu, who has our thanks for the detailed report.

### Patches

The problem has been fixed in Puma 3.12.5 and Puma 4.3.4.

### For more information

If you have any questions or comments about this advisory:

* Open an issue in [Puma](https://github.com/puma/puma) * See our [security policy](https://github.com/puma/puma/security/policy)

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems / puma
Introduced in: 0 Fixed in: 3.12.5
Fix bundle update puma
RubyGems / puma
Introduced in: 4.0.0 Fixed in: 4.3.4
Fix bundle update puma

References