{"schema_version":"1.7.5","id":"GHSA-q28m-8xjw-8vr5","published":"2021-05-18T01:27:15Z","modified":"2026-07-08T06:00:01.447117147Z","aliases":["CVE-2021-29509"],"summary":"Puma's Keepalive Connections Causing Denial Of Service","details":"This vulnerability is related to [CVE-2019-16770](https://github.com/puma/puma/security/advisories/GHSA-7xx3-m584-x994).\n\n### Impact\n\nThe fix for CVE-2019-16770 was incomplete. The original fix only protected existing connections that had already been accepted from having their requests starved by greedy persistent-connections saturating all threads in the same process. However, new connections may still be starved by greedy persistent-connections saturating all threads in all processes in the cluster.\n\nA `puma` server which received more concurrent `keep-alive` connections than the server had threads in its threadpool would service only a subset of connections, denying service to the unserved connections.\n\n### Patches\n\nThis problem has been fixed in `puma` 4.3.8 and 5.3.1.\n\n### Workarounds\n\nSetting `queue_requests false` also fixes the issue. This is not advised when using `puma` without a reverse proxy, such as `nginx` or `apache`, because you will open yourself to slow client attacks (e.g. [slowloris](https://en.wikipedia.org/wiki/Slowloris_(computer_security))).\n\nThe fix is very small. [A git patch is available here](https://gist.github.com/nateberkopec/4b3ea5676c0d70cbb37c82d54be25837) for those using [unsupported versions](https://github.com/puma/puma/security/policy#supported-versions) of Puma.\n\n### For more information\n\nIf you have any questions or comments about this advisory:\n\n* Open an issue in [Puma](https://github.com/puma/puma).\n* To report problems with this fix or to report another vulnerability, see [our security policy.](https://github.com/puma/puma/security/policy)\n\n### Acknowledgements\n\nThank you to @MSP-Greg, @wjordan and @evanphx for their review on this issue. \n\nThank you to @ioquatix for providing a modified fork of `wrk` which made debugging this issue much easier.","affected":[{"package":{"name":"puma","ecosystem":"RubyGems","purl":"pkg:gem/puma"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.3.8"}]}],"versions":["0.8.0","0.8.1","0.8.2","0.9.0","0.9.1","0.9.2","0.9.3","0.9.4","0.9.5","1.0.0","1.1.0","1.1.1","1.2.0","1.2.1","1.2.2","1.3.0","1.3.1","1.4.0","1.5.0","1.6.0","1.6.1","1.6.2","1.6.3","2.0.0","2.0.0.b1","2.0.0.b2","2.0.0.b3","2.0.0.b4","2.0.0.b5","2.0.0.b6","2.0.0.b7","2.0.1","2.1.0","2.1.1","2.10.0","2.10.1","2.10.2","2.11.0","2.11.1","2.11.2","2.11.3","2.12.0","2.12.1","2.12.2","2.12.3","2.13.0","2.13.1","2.13.2","2.13.3","2.13.4","2.14.0","2.15.0","2.15.1","2.15.2","2.15.3","2.16.0","2.2.0","2.2.1","2.2.2","2.3.0","2.3.1","2.3.2","2.4.0","2.4.1","2.5.0","2.5.1","2.6.0","2.7.0","2.7.1","2.8.0","2.8.1","2.8.2","2.9.0","2.9.1","2.9.2","3.0.0","3.0.0.rc1","3.0.1","3.0.2","3.1.0","3.1.1","3.10.0","3.11.0","3.11.1","3.11.2","3.11.3","3.11.4","3.12.0","3.12.1","3.12.2","3.12.4","3.12.5","3.12.6","3.2.0","3.3.0","3.4.0","3.5.0","3.5.1","3.5.2","3.6.0","3.6.1","3.6.2","3.7.0","3.7.1","3.8.0","3.8.1","3.8.2","3.9.0","3.9.1","4.0.0","4.0.1","4.1.0","4.1.1","4.2.0","4.2.1","4.3.0","4.3.1","4.3.3","4.3.4","4.3.5","4.3.6","4.3.7"],"database_specific":{"last_known_affected_version_range":"<= 4.3.7","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/05/GHSA-q28m-8xjw-8vr5/GHSA-q28m-8xjw-8vr5.json"}},{"package":{"name":"puma","ecosystem":"RubyGems","purl":"pkg:gem/puma"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.0.0"},{"fixed":"5.3.1"}]}],"versions":["5.0.0","5.0.1","5.0.2","5.0.3","5.0.4","5.1.0","5.1.1","5.2.0","5.2.1","5.2.2","5.3.0"],"database_specific":{"last_known_affected_version_range":"<= 5.3.0","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/05/GHSA-q28m-8xjw-8vr5/GHSA-q28m-8xjw-8vr5.json"}}],"references":[{"type":"WEB","url":"https://github.com/puma/puma/security/advisories/GHSA-q28m-8xjw-8vr5"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-29509"},{"type":"WEB","url":"https://gist.github.com/nateberkopec/4b3ea5676c0d70cbb37c82d54be25837"},{"type":"PACKAGE","url":"https://github.com/puma/puma"},{"type":"WEB","url":"https://github.com/puma/puma/security/policy"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/puma/CVE-2021-29509.yml"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2022/08/msg00015.html"},{"type":"WEB","url":"https://rubygems.org/gems/puma"},{"type":"WEB","url":"https://security.gentoo.org/glsa/202208-28"}],"database_specific":{"cwe_ids":["CWE-400"],"github_reviewed":true,"github_reviewed_at":"2021-05-18T01:26:55Z","nvd_published_at":"2021-05-11T17:15:00Z","severity":"HIGH"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}