CVE-2025-26803

NameCVE-2025-26803
DescriptionThe http parser in Phusion Passenger 6.0.21 through 6.0.25 before 6.0.26 allows a denial of service during parsing of a request with an invalid HTTP method.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1098909

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
passenger (PTS)bullseye5.0.30-1.2+deb11u1fixed
bookworm6.0.17+ds-1fixed
sid, trixie6.0.24+ds-3vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
passengersourcebullseye(not affected)
passengersourcebookworm(not affected)
passengersource(unstable)(unfixed)1098909

Notes

[bookworm] - passenger <not-affected> (Vulnerable code introduced later)
[bullseye] - passenger <not-affected> (Vulnerable code introduced later)
https://blog.phusion.nl/2025/02/19/passenger-6-0-26/
Introduced with: https://github.com/phusion/passenger/commit/f51fc490472882b236c52d708d605a1961dacb18 (release-6.0.21)
Fixed by: https://github.com/phusion/passenger/commit/bb15591646687064ab2d578d5f9660b2a4168017 (release-6.0.26)

Search for package or bug name: Reporting problems