CVE-2025-26803

MEDIUM5.3EPSS 0.27%

Phusion Passenger denial of service

Published: 2/24/2025Modified: 3/2/2025
Also known as:GHSA-2cj2-qqxj-5m3rBIT-passenger-2025-26803BIT-passenger-apache-module-2025-26803BIT-passenger-nginx-module-2025-26803

Description

The http parser in Phusion Passenger 6.0.21 through 6.0.25 before 6.0.26 allows a denial of service during parsing of a request with an invalid HTTP method.

Affected packages (5)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

References (10)