CVE-2026-68006: Puma vulnerability
Published Sep 10, 2026
·Updated
An issue in Puma v.5.0.0 and before v.8.0.3 allows an attacker to execute arbitrary code via the ext/pumahttp11/http11parser.rl file
Affected Software
1 affected component
Puma<=8.0.3
Event History
Sep 10, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
Which Puma versions should be prioritized for review?
The reported affected range includes Puma v5.0.0 and versions before v8.0.3. Deployments in that stated range should be reviewed first.