Executive brief
Puma is a popular web server used to run Ruby applications. A vulnerability in its handling of the PROXY protocol allows an attacker to crash the server or significantly slow it down by sending a continuous stream of data without the expected line endings. This can lead to a total service outage (denial of service) as the server consumes all available memory and processor power trying to process the malicious request.
Technical details
Puma is vulnerable to uncontrolled resource consumption (CWE-400) within its PROXY protocol v1 parsing logic. When the 'proxy_protocol: :v1' configuration is enabled, the server reads incoming bytes into an internal pre-parse buffer while searching for a CRLF (\r\n) sequence. Because there is no limit on the size of this buffer before the CRLF is found, a remote, unauthenticated attacker can establish a TCP connection and send a continuous stream of bytes without line endings. This results in unbounded memory growth and high CPU usage as the server repeatedly scans the ever-increasing buffer. The vulnerability is resolved in versions 7.2.1 and 8.0.2 by enforcing maximum line lengths and anchoring the protocol regex.
Affected products
- Puma Puma >= 5.5.0, < 7.2.1; >= 8.0.0, < 8.0.2
Timeline
- 2026-05-27: advisory: GitHub Security Advisory published
- 2026-05-27: patched: Versions 7.2.1 and 8.0.2 released
- 2026-07-14: disclosed: CVE-2026-47736 published to NVD
References
- https://github.com/puma/puma/commit/439c6136d9c2275721b7864db3ee78af7c80889f
- https://github.com/puma/puma/commit/ebe9db3929ab8299d19c8f5b41e8ef4f4b22fa58
- https://github.com/puma/puma/releases/tag/v7.2.1
- https://github.com/puma/puma/releases/tag/v8.0.2
- https://github.com/puma/puma/security/advisories/GHSA-qpgp-93vx-g8v8