Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2020-5249

21
FAUCET Score

CVE-2020-5249 describes an HTTP Response Splitting vulnerability in Puma (RubyGem) versions prior to 4.3.3 and 3.12.4. This flaw allows an attacker to inject malicious content, such as additional headers or a new response body, if the application processes untrusted input in an early-hints header. Rated Medium severity (CVSS 6.5), the vulnerability has a network attack vector and low attack complexity, potentially leading to high integrity impact, though it does not directly affect confidentiality or availability. While not an attack itself, it serves as a vector for other attacks like Cross-Site Scripting (XSS). There is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. The vulnerability has received minimal community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
<= 3.12.3CPE matchmatch criteria
cpe:2.3:a:puma:puma:*:*:*:*:*:ruby:*:*
>= 4.0.0, <= 4.3.2CPE matchmatch criteria
cpe:2.3:a:puma:puma:*:*:*:*:*:ruby:*:*

CVSS Data

CVSS version used by this source: 3.1

6.5MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
LOW
Exploitability Score
2.3
Impact Score
3.7
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.57%
Probability of exploitation in next 30 days
EPSS Percentile
72.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0157 is in the 86th percentile among its peer group of 21,958 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (6)

github_advisorypatch availablevia nvd_reference
View patch
rubygemspatch availablevia ghsa
Product: pumaFixed in: 3.12.4
rubygemspatch availablevia ghsa
Product: pumaFixed in: 4.3.3
redhatend of lifevia redhat_api
Product: CloudForms Management Engine 5Fixed in: rubygem-puma
redhatend of lifevia redhat_api
Product: Red Hat Software CollectionsFixed in: rh-ror50-rubygem-puma
redhatend of lifevia redhat_api
Product: Red Hat Storage 3Fixed in: rubygem-puma

Vendor Advisories (2)

rubygemsGHSA-33vf-4xgg-9r58medium

HTTP Response Splitting (Early Hints) in Puma

Mar 3, 2020
redhatCVE-2020-5249Moderate

rubygem-puma: attacker is able to use carriage return character to insert malicious content (HTTP Response Splitting), this could lead to XSS

Mar 2, 2020

References

github.com / puma/puma/commit/c22712fc93284a45a93f9ad7023888f3a65524f3
PatchThird Party Advisory
github.com / puma/puma/security/advisories/GHSA-33vf-4xgg-9r58
Third Party Advisory
github.com / puma/puma/security/advisories/GHSA-84j7-475p-hp8v
Third Party Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/BMJ3CGZ3DLBJ5WUUKMI5ZFXFJQMXJZIK
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/DIHVO3CQMU7BZC7FCTSRJ33YDNS3GFPK
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/NJ3LL5F5QADB6LM46GXZETREAKZMQNRD
owasp.org / www-community/attacks/HTTP_Response_Splitting
Third Party Advisory