CVE-2025-26803
The http parser in Phusion Passenger 6.0.21 through 6.0.25 before 6.0.26 allows a denial of service during parsing of a request with an invalid HTTP method.
Vendor
Product
CWE
Yayın Tarihi
2025-02-24 16:15:15
Güncelleme
2025-02-28 17:21:55
Source Identifier
cve@mitre.org
KEV Date Added
-
Kategoriler
Referanslar
https://blog.phusion.nl/2025/02/19/passenger-6-0-26/
https://github.com/phusion/passenger/commit/bb15591646687064ab2d578d5f9660b2a4168017
https://github.com/phusion/passenger/compare/release-6.0.25...release-6.0.26
https://github.com/phusion/passenger/releases/tag/release-6.0.26
https://www.phusionpassenger.com/support