VYPR
High severity7.5NVD Advisory· Published Jul 14, 2026· Updated Jul 15, 2026

CVE-2026-47736

CVE-2026-47736

Description

Puma is a Ruby/Rack web server built for parallelism. From 5.5.0 until 7.2.1 and 8.0.2, when PROXY protocol v1 support is enabled, Puma reads incoming bytes into an internal buffer while waiting for CRLF to determine whether a PROXY v1 line is present, allowing an attacker that continuously sends bytes without CRLF to cause unbounded in-process memory growth and additional CPU cost from repeatedly scanning the growing buffer. This issue is fixed in versions 7.2.1 and 8.0.2.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
pumaRubyGems
>= 8.0.0, < 8.0.28.0.2
pumaRubyGems
>= 5.5.0, < 7.2.17.2.1

Affected products

24

Patches

Vulnerability mechanics

References

8

News mentions

0

No linked articles in our index yet.