RubySec

Providing security resources for the Ruby community

CVE-2025-26803 (passenger): Phusion Passenger denial of service

Phusion Passenger denial of service

Published: February 24, 2025

SECURITY IDENTIFIERS

GEM

passenger

SEVERITY

CVSS v3.x: 5.3 (Medium)

UNAFFECTED VERSIONS

< 6.0.21

PATCHED VERSIONS

>= 6.0.26

DESCRIPTION

The http parser in Phusion Passenger 6.0.21 through 6.0.25 before 6.0.26 allows a denial of service during parsing of a request with an invalid HTTP method.

RELATED