CVE

CVE-2019-16770

CVE-2019-16770

A poorly-behaved client could use keepalive requests to monopolize Puma’s reactor and create a denial of service attack. If more keepalive connections to Puma are opened than there are threads available, additional connections will wait permanently if the attacker sends requests frequently enough.

Source: CVE-2019-16770

Exit mobile version