Skip to content

Commit 61e4f1f

Browse files
jasnowRubySec CI
authored and
RubySec CI
committed
Updated advisory posts against rubysec/ruby-advisory-db@deb44c6
1 parent b2a7999 commit 61e4f1f

File tree

1 file changed

+32
-0
lines changed

1 file changed

+32
-0
lines changed
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,32 @@
1+
---
2+
layout: advisory
3+
title: 'CVE-2025-26803 (passenger): Phusion Passenger denial of service'
4+
comments: false
5+
categories:
6+
- passenger
7+
advisory:
8+
gem: passenger
9+
cve: 2025-26803
10+
ghsa: 2cj2-qqxj-5m3r
11+
url: https://github.com/advisories/GHSA-2cj2-qqxj-5m3r
12+
title: Phusion Passenger denial of service
13+
date: 2025-02-24
14+
description: |
15+
The http parser in Phusion Passenger 6.0.21 through 6.0.25
16+
before 6.0.26 allows a denial of service during parsing of
17+
a request with an invalid HTTP method.
18+
cvss_v3: 5.3
19+
unaffected_versions:
20+
- "< 6.0.21"
21+
patched_versions:
22+
- ">= 6.0.26"
23+
related:
24+
url:
25+
- https://nvd.nist.gov/vuln/detail/CVE-2025-26803
26+
- https://blog.phusion.nl/2025/02/19/passenger-6-0-26
27+
- https://github.com/phusion/passenger/compare/release-6.0.25...release-6.0.26
28+
- https://github.com/phusion/passenger/releases/tag/release-6.0.26
29+
- https://github.com/phusion/passenger/commit/bb15591646687064ab2d578d5f9660b2a4168017
30+
- https://www.phusionpassenger.com/support
31+
- https://github.com/advisories/GHSA-2cj2-qqxj-5m3r
32+
---

0 commit comments

Comments
 (0)