Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2020-5247

20
FAUCET Score

CVE-2020-5247 is an HTTP Response Splitting vulnerability affecting Puma (RubyGem) versions prior to 4.3.2 and 3.12.3, as well as related distributions like Debian and Fedora. It allows an attacker to inject malicious content, such as additional headers or a new response body, by including newline characters in untrusted input within a response header. This vulnerability carries a CVSS score of 7.5 (High), indicating a network-based attack with low complexity and a high impact on integrity, though it is not an attack in itself but a vector for others like XSS. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
<= 3.12.3CPE matchmatch criteria
cpe:2.3:a:puma:puma:*:*:*:*:*:ruby:*:*
>= 4.0.0, <= 4.3.2CPE matchmatch criteria
cpe:2.3:a:puma:puma:*:*:*:*:*:ruby:*:*
<= 2.3.0CPE matchmatch criteria
cpe:2.3:a:ruby-lang:ruby:*:*:*:*:*:*:*:*
>= 2.4.0, <= 2.4.7CPE matchmatch criteria
cpe:2.3:a:ruby-lang:ruby:*:*:*:*:*:*:*:*
>= 2.5.0, <= 2.5.6CPE matchmatch criteria
cpe:2.3:a:ruby-lang:ruby:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

6.5MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
LOW
Exploitability Score
2.3
Impact Score
3.7
CvssVersion
3.1

Exploit Intelligence

EPSS Score
2.55%
Probability of exploitation in next 30 days
EPSS Percentile
83.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0255 is in the 70th percentile among its peer group of 51,551 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (11)

microsoftpatch availablevia msrc
Product: cm1 ruby 2.6.7-1 on CBL Mariner 1.0Fixed in: 2.6.7-1
microsoftpatch availablevia msrc
Product: 17016-16820Fixed in: 2.6.7-1
microsoftpatch availablevia msrc
Product: CBL Mariner 1.0 x64Fixed in: 2.6.7-1
microsoftpatch availablevia msrc
Product: CBL Mariner 1.0 ARMFixed in: 2.6.7-1
rubygemspatch availablevia ghsa
Product: pumaFixed in: 3.12.4
rubygemspatch availablevia ghsa
Product: pumaFixed in: 4.3.3
github_advisoryworkaround availablevia nvd_reference
View patch
redhatno patchvia redhat_api
Product: Red Hat 3scale API Management Platform 2Fixed in: system
redhatend of lifevia redhat_api
Product: Red Hat Storage 3Fixed in: rubygem-puma
redhatend of lifevia redhat_api
Product: Red Hat Software CollectionsFixed in: rh-ror50-rubygem-puma
redhatend of lifevia redhat_api
Product: CloudForms Management Engine 5Fixed in: rubygem-puma

Vendor Advisories (4)

microsoft2020-Sep/CVE-2020-5247

CVE-2020-5247

Sep 8, 2020
redhatCVE-2020-5247Moderate

rubygem-puma: attacker is able to use newline characters to insert malicious content (HTTP Response Splitting), this could lead to XSS

Mar 2, 2020
rubygemsGHSA-84j7-475p-hp8vmedium

HTTP Response Splitting in Puma

Feb 28, 2020
microsoft2020-Feb/CVE-2020-5247Important

HTTP Response Splitting in Puma

Feb 11, 2020

References

github.com / puma/puma/security/advisories/GHSA-84j7-475p-hp8v
MitigationThird Party Advisory
lists.debian.org / debian-lts-announce/2022/05/msg00034.html
Mailing ListThird Party Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/BMJ3CGZ3DLBJ5WUUKMI5ZFXFJQMXJZIK
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/DIHVO3CQMU7BZC7FCTSRJ33YDNS3GFPK
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/NJ3LL5F5QADB6LM46GXZETREAKZMQNRD
owasp.org / www-community/attacks/HTTP_Response_Splitting
Third Party Advisory
ruby-lang.org / en/news/2019/10/01/http-response-splitting-in-webrick-cve-2019-16254
Vendor Advisory