UBUNTU-CVE-2020-11076
High
UBUNTU-CVE-2020-11076
In Puma (RubyGem) before 4.3.4 and 3.12.5, an attacker could smuggle an HTTP response, by using an invalid transfer-encoding header. The problem has been fixed in Puma 3.12.5 and Puma 4.3.4.
Exploit probability
Not scored
Published
May 22, 2020
Required by
Not available
Last source change
February 4, 2026
02 / AFFECTED SOFTWARE
Affected packages
3 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Open Source Vulnerabilities
UBUNTU-CVE-2020-11076
View original source
In Puma (RubyGem) before 4.3.4 and 3.12.5, an attacker could smuggle an HTTP response, by using an invalid transfer-encoding header. The problem has been fixed in Puma 3.12.5 and Puma 4.3.4.
05 / REFERENCES
Further evidence
- https://github.com/puma/puma/blob/master/History.md#434435-and-31253126--2020-05-22
- https://github.com/puma/puma/commit/f24d5521295a2152c286abb0a45a1e1e2bd275bd
- https://github.com/puma/puma/security/advisories/GHSA-x7jg-6pwg-fx5h
- https://ubuntu.com/security/CVE-2020-11076
- https://ubuntu.com/security/notices/USN-6682-1
- https://www.cve.org/CVERecord?id=CVE-2020-11076