CVE-2025-26803: High severity Phusion Passenger vulnerability
Published Feb 24, 2025
·Updated
The http parser in Phusion Passenger 6.0.21 through 6.0.25 before 6.0.26 allows a denial of service during parsing of a request with an invalid HTTP method.
Affected Software
2 affected componentsFixes available
rubygems/passenger>=6.0.21<6.0.26
6.0.26
Phusion Passenger>=6.0.21<6.0.26
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
rubygems/passengerto a version that resolves this vulnerability.Fixed in 6.0.26
Event History
Feb 24, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Advisory Published
via GitHub·06:32 PM
Jun 14, 57134
Event
via FIRST·12:05 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-26803?
CVE-2025-26803 is classified as a denial of service vulnerability.
2
How do I fix CVE-2025-26803?
To fix CVE-2025-26803, upgrade Phusion Passenger to version 6.0.26 or later.
3
What versions of Phusion Passenger are affected by CVE-2025-26803?
Phusion Passenger versions 6.0.21 through 6.0.25 are affected by CVE-2025-26803.
4
Can CVE-2025-26803 be exploited remotely?
Yes, CVE-2025-26803 can potentially be exploited remotely if the server processes a request with an invalid HTTP method.
5
What impact does CVE-2025-26803 have on applications?
CVE-2025-26803 can lead to a Denial of Service, causing the application to become unresponsive.