It was discovered that Puma incorrectly handled parsing certain headers. A remote attacker could possibly use this issue to overwrite header values set by intermediate proxies by providing duplicate headers containing underscore characters.
{ "availability": "No subscription required", "binaries": [ { "binary_version": "6.4.2-4ubuntu4.3", "binary_name": "puma" } ] }