Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-47737

32
FAUCET Score

Puma is a Ruby/Rack web server built for parallelism. From 5.5.0 until 7.2.1 and 8.0.2, Puma is vulnerable to source IP spoofing when set_remote_address proxy_protocol: :v1 is enabled and persistent connections are used because Puma incorrectly re-parses PROXY protocol headers after each keep-alive request on the same connection, allowing an attacker to inject a second PROXY header and overwrite REMOTE_ADDR. This issue is fixed in versions 7.2.1 and 8.0.2.

First published: Jul 14, 2026Last modified: Jul 14, 2026

Impacted Technologies

VendorProductVersion(s)CPE
PumaPuma
>= 5.5.0, < 7.2.1, >= 8.0.0, < 8.0.2CNA affected

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.18%
Probability of exploitation in next 30 days
EPSS Percentile
7.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0018 is in the 0th percentile among its peer group of 51,553 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

rubygemspatch availablevia ghsa
Product: pumaFixed in: 8.0.2
rubygemspatch availablevia ghsa
Product: pumaFixed in: 7.2.1

Vendor Advisories (1)

rubygemsGHSA-2vqw-3mp8-cgmxhigh

Puma PROXY Protocol v1 Accepts Repeated Protocol Headers on Persistent Connections

Jun 9, 2026

References

github.com / puma/puma/commit/439c6136d9c2275721b7864db3ee78af7c80889f
github.com / puma/puma/commit/ebe9db3929ab8299d19c8f5b41e8ef4f4b22fa58
github.com / puma/puma/pull/3944
github.com / puma/puma/pull/3947
github.com / puma/puma/releases/tag/v7.2.1
github.com / puma/puma/releases/tag/v8.0.2
github.com / puma/puma/security/advisories/GHSA-2vqw-3mp8-cgmx