Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:34886
HistoryMar 31, 2022 - 4:16 a.m.

HTTP Request Smuggling

2022-03-3104:16:15
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
22
puma
http request smuggling
rfc7230
proxy
vulnerability

EPSS

0.009

Percentile

83.2%

puma is vulnerable to HTTP request smuggling. When using the library behind a proxy that does not properly validate the incoming HTTP requests with the RFC7230 standard, puma and the frontend proxy contradict on where one request starts and where it ends, resulting in requests to be smuggled via the front-end proxy.