Bug 2500584 (CVE-2026-47737) - CVE-2026-47737 puma: Puma: Source IP spoofing via PROXY protocol header re-parsing
Summary: CVE-2026-47737 puma: Puma: Source IP spoofing via PROXY protocol header re-pa...
Keywords:
Status: NEW
Alias: CVE-2026-47737
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2500847
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-07-14 20:04 UTC by OSIDB Bzimport
Modified: 2026-07-15 10:10 UTC (History)
24 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-07-14 20:04:48 UTC
Puma is a Ruby/Rack web server built for parallelism. From 5.5.0 until 7.2.1 and 8.0.2, Puma is vulnerable to source IP spoofing when set_remote_address proxy_protocol: :v1 is enabled and persistent connections are used because Puma incorrectly re-parses PROXY protocol headers after each keep-alive request on the same connection, allowing an attacker to inject a second PROXY header and overwrite REMOTE_ADDR. This issue is fixed in versions 7.2.1 and 8.0.2.


Note You need to log in before you can comment on or make changes to this bug.