{"id":"CVE-2026-47737","aliases":["GHSA-2vqw-3mp8-cgmx"],"url":"https://o3.security/vulnerability/CVE-2026-47737","summary":"Puma PROXY Protocol v1 Accepts Repeated Protocol Headers on Persistent Connections","details":"Puma is a Ruby/Rack web server built for parallelism. From 5.5.0 until 7.2.1 and 8.0.2, Puma is vulnerable to source IP spoofing when set_remote_address proxy_protocol: :v1 is enabled and persistent connections are used because Puma incorrectly re-parses PROXY protocol headers after each keep-alive request on the same connection, allowing an attacker to inject a second PROXY header and overwrite REMOTE_ADDR. This issue is fixed in versions 7.2.1 and 8.0.2.","published":"2026-07-14T19:45:16.648Z","modified":"2026-08-12T03:51:36.316962906Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"},"epss":{"score":0.00266,"percentile":0.18015,"asOf":"2026-08-24"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"RubyGems","name":"puma","fixedVersion":"8.0.2"},{"ecosystem":"RubyGems","name":"puma","fixedVersion":"7.2.1"}],"fix":{"url":"https://github.com/puma/puma/commit/439c6136d9c2275721b7864db3ee78af7c80889f","label":"puma/puma@439c613"},"references":[{"type":"WEB","url":"https://github.com/puma/puma/releases/tag/v7.2.1"},{"type":"WEB","url":"https://github.com/puma/puma/releases/tag/v8.0.2"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/47xxx/CVE-2026-47737.json"},{"type":"ADVISORY","url":"https://github.com/puma/puma/security/advisories/GHSA-2vqw-3mp8-cgmx"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-47737"},{"type":"FIX","url":"https://github.com/puma/puma/commit/439c6136d9c2275721b7864db3ee78af7c80889f"},{"type":"FIX","url":"https://github.com/puma/puma/commit/ebe9db3929ab8299d19c8f5b41e8ef4f4b22fa58"},{"type":"FIX","url":"https://github.com/puma/puma/pull/3944"},{"type":"FIX","url":"https://github.com/puma/puma/pull/3947"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:36.316962906Z"}}