CVE-2024-21647: HTTP Request/Response Smuggling in puma

Published Jan 8, 2024
·
Updated

Impact Prior to versions 6.4.2 and 5.6.8, puma exhibited dangerous behavior when parsing chunked transfer encoding bodies.

Fixed versions limit the size of chunk extensions. Without this limit, an attacker could cause unbounded resource (CPU, network bandwidth) consumption.

Patches

The vulnerability has been fixed in 6.4.2 and 5.6.8.

Workarounds

No known workarounds.

References

HTTP Request Smuggling Open an issue in Puma See our security policy

Other sources

Impact Prior to versions 6.4.2 and 5.6.8, puma exhibited incorrect behavior when parsing chunked transfer encoding bodies in a way that allowed HTTP request smuggling.

Fixed versions limit the size of chunk extensions. Without this limit, an attacker could cause unbounded resource (CPU, network bandwidth) consumption.

Patches

The vulnerability has been fixed in 6.4.2 and 5.6.8.

Workarounds

No known workarounds.

References

HTTP Request Smuggling Open an issue in Puma See our security policy

Puma is a web server for Ruby/Rack applications built for parallelism. Prior to version 6.4.2, puma exhibited incorrect behavior when parsing chunked transfer encoding bodies in a way that allowed HTTP request smuggling. Fixed versions limits the size of chunk extensions. Without this limit, an attacker could cause unbounded resource (CPU, network bandwidth) consumption. This vulnerability has been fixed in versions 6.4.2 and 5.6.8.

Ubuntu

Affected Software

11 affected componentsFixes available
rubygems/puma<5.6.8
5.6.8
rubygems/puma>=6.0.0<6.4.2
6.4.2
debian/puma<=3.12.0-2+deb10u2, <=3.12.0-2+deb10u3, <=4.3.8-1, <=4.3.8-1+deb11u2, <=5.6.5-3
6.4.2-4
ubuntu/puma<3.12.4-1ubuntu2+
3.12.4-1ubuntu2+
ubuntu/puma<5.5.2-2ubuntu2+
5.5.2-2ubuntu2+
ubuntu/puma<5.6.5-3ubuntu1.2
5.6.5-3ubuntu1.2
ubuntu/puma<5.6.5-4ubuntu2.1
5.6.5-4ubuntu2.1
redhat/puma<6.4.2
6.4.2
redhat/puma<5.6.8
5.6.8
PUMA Puma Ruby<5.6.8
PUMA Puma Ruby>=6.0.0<6.4.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade rubygems/puma to a version that resolves this vulnerability.

    Fixed in 5.6.8
  2. Upgrade

    Upgrade rubygems/puma to a version that resolves this vulnerability.

    Fixed in 6.4.2
  3. Upgrade

    Upgrade debian/puma to a version that resolves this vulnerability.

    Fixed in 6.4.2-4
  4. Upgrade

    Upgrade ubuntu/puma to a version that resolves this vulnerability.

    Fixed in 3.12.4-1ubuntu2+
  5. Upgrade

    Upgrade ubuntu/puma to a version that resolves this vulnerability.

    Fixed in 5.5.2-2ubuntu2+
  6. Upgrade

    Upgrade ubuntu/puma to a version that resolves this vulnerability.

    Fixed in 5.6.5-3ubuntu1.2
  7. Upgrade

    Upgrade ubuntu/puma to a version that resolves this vulnerability.

    Fixed in 5.6.5-4ubuntu2.1
  8. Upgrade

    Upgrade redhat/puma to a version that resolves this vulnerability.

    Fixed in 6.4.2
  9. Upgrade

    Upgrade redhat/puma to a version that resolves this vulnerability.

    Fixed in 5.6.8
  10. Upgrade

    Upgrade puma to a version that resolves this vulnerability.

    Fixed in 6.4.2
  11. Upgrade

    Upgrade puma to a version that resolves this vulnerability.

    Fixed in 5.6.8

Event History

Jan 8, 2024
CVE Published
via Ubuntu·12:00 AM
CVE Published
via MITRE·01:45 PM
Data Sourced
via MITRE·01:45 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Advisory Published
03:56 PM
Data Sourced
via Red Hat·10:09 PM
DescriptionSeverityAffected Software
Jan 25, 2024
Data Sourced
via Launchpad·02:39 PM
Description

Parent advisories

This vulnerability appears in the following advisories.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2024-21647?

CVE-2024-21647 is considered a high severity vulnerability due to the potential for unbounded resource consumption.

2

How do I fix CVE-2024-21647?

To resolve CVE-2024-21647, upgrade to Puma version 5.6.8 or 6.4.2 and later.

3

What types of systems are affected by CVE-2024-21647?

CVE-2024-21647 affects versions of Puma prior to 6.4.2 and 5.6.8 across various platforms including Debian, Ubuntu, and Red Hat.

4

What are the consequences of not addressing CVE-2024-21647?

Failing to address CVE-2024-21647 can lead to denial of service conditions due to excessive resource usage.

5

Is there a workaround for CVE-2024-21647 until I can upgrade?

There are no recommended workarounds for CVE-2024-21647; upgrading is the best solution.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203