Related Vulnerabilities: CVE-2021-41136  

Using puma with a proxy which forwards LF characters as line endings could allow HTTP request smuggling. Puma is only aware of a single proxy server which has this behavior.

Severity Low

Remote Yes

Type Unknown

Description

Using puma with a proxy which forwards LF characters as line endings could allow HTTP request smuggling. Puma is only aware of a single proxy server which has this behavior.

AVG-2764 ruby-puma 5.6.3-1 5.6.4-1 Medium Unknown

https://github.com/puma/puma/commit/acdc3ae571dfae0e045cf09a295280127db65c7f
https://github.com/puma/puma/security/advisories/GHSA-48w2-rm65-62xx