CRITICAL
Puma
CVE published 2026-09-10
CVE-2026-68006
A critical vulnerability was found in Puma versions up to 8.0.3. An attacker could potentially execute arbitrary code via the ext/puma_http11/http11_parser.rl file. The CVE record was published on 2026-09-10T18:18:04.960Z and was last modified on 2026-09-14T19:17:39.727Z. The NVD entry is currently Awaiting Analysis. Defenders using Puma versions up to 8.0.3 should assess their exposure and prioritize rem [truncated]