GHSA-2cj2-qqxj-5m3r

Suggest an improvement
Source
https://github.com/advisories/GHSA-2cj2-qqxj-5m3r
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/02/GHSA-2cj2-qqxj-5m3r/GHSA-2cj2-qqxj-5m3r.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-2cj2-qqxj-5m3r
Aliases
Published
2025-02-24T18:32:42Z
Modified
2025-03-02T08:11:48.315117Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L CVSS Calculator
Summary
Phusion Passenger denial of service
Details

The http parser in Phusion Passenger 6.0.21 through 6.0.25 before 6.0.26 allows a denial of service during parsing of a request with an invalid HTTP method.

Database specific
{
    "nvd_published_at": "2025-02-24T16:15:15Z",
    "cwe_ids": [
        "CWE-908"
    ],
    "severity": "MODERATE",
    "github_reviewed": true,
    "github_reviewed_at": "2025-02-24T20:49:38Z"
}
References

Affected packages

RubyGems / passenger

Package

Name
passenger
Purl
pkg:gem/passenger

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.0.21
Fixed
6.0.26

Affected versions

6.*

6.0.21
6.0.22
6.0.23
6.0.24
6.0.25