{"api_version":"v1","generated_at":"2026-10-07T23:55:00+00:00","product":{"cve_count":12,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-puma-puma-93b98dc2abe7","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/puma","name":"Puma","next_cursor":null,"observations":[{"affected":">= 5.5.0, < 7.2.1; >= 8.0.0, < 8.0.2","affected_versions_present":true,"cve_id":"CVE-2026-47736","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-47736","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-07-15T14:28:29.155Z","patch_url":"","primary_source":"","published":"2026-07-14T19:54:26.229Z"},{"affected":">= 5.5.0, < 7.2.1; >= 8.0.0, < 8.0.2","affected_versions_present":true,"cve_id":"CVE-2026-47737","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-47737","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-07-15T14:10:20.444Z","patch_url":"","primary_source":"","published":"2026-07-14T19:45:16.648Z"},{"affected":">= 6.0.0, < 6.4.3; < 5.6.9","affected_versions_present":true,"cve_id":"CVE-2024-45614","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-45614","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-11-03T22:15:51.621Z","patch_url":"","primary_source":"","published":"2024-09-19T22:42:33.974Z"},{"affected":"< 5.6.8; >= 6.0.0, < 6.4.2","affected_versions_present":true,"cve_id":"CVE-2024-21647","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-21647","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-11-03T21:53:27.921Z","patch_url":"https://github.com/puma/puma/commit/5fc43d73b6ff193325e657a24ed76dec79133e93","primary_source":"","published":"2024-01-08T13:45:27.510Z"},{"affected":"< 5.6.7; >= 6.0.0, < 6.3.1","affected_versions_present":true,"cve_id":"CVE-2023-40175","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-40175","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-10-07T20:04:46.951Z","patch_url":"https://github.com/puma/puma/commit/690155e7d644b80eeef0a6094f9826ee41f1080a","primary_source":"","published":"2023-08-18T21:35:47.577Z"},{"affected":"< 4.3.12; >= 5.0.0, < 5.6.4","affected_versions_present":true,"cve_id":"CVE-2022-24790","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-24790","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-04-23T18:43:11.083Z","patch_url":"https://github.com/puma/puma/commit/5bb7d202e24dec00a898dca4aa11db391d7787a5","primary_source":"","published":"2022-03-30T21:50:09.000Z"},{"affected":">= 5.0.0, < 5.6.2; < 4.3.11","affected_versions_present":true,"cve_id":"CVE-2022-23634","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-23634","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-04-23T19:05:33.266Z","patch_url":"https://github.com/puma/puma/security/advisories/GHSA-rmj8-8hhh-gv5h","primary_source":"","published":"2022-02-11T21:40:11.000Z"},{"affected":">= 5.0.0, < 5.5.1; < 4.3.9","affected_versions_present":true,"cve_id":"CVE-2021-41136","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-41136","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-05-27T15:16:10.431Z","patch_url":"https://github.com/puma/puma/commit/acdc3ae571dfae0e045cf09a295280127db65c7f","primary_source":"","published":"2021-10-12T15:30:11.000Z"},{"affected":"< 4.3.8; >= 5.0.0, < 5.3.1","affected_versions_present":true,"cve_id":"CVE-2021-29509","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-29509","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-03T22:11:05.438Z","patch_url":"https://github.com/puma/puma/security/advisories/GHSA-q28m-8xjw-8vr5","primary_source":"","published":"2021-05-11T16:50:11.000Z"},{"affected":"< 3.12.6; >= 4.0.0, < 4.3.5","affected_versions_present":true,"cve_id":"CVE-2020-11077","cve_url":"https://cve.blacktree.nl/cve/CVE-2020-11077","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-08-04T11:21:14.618Z","patch_url":"","primary_source":"","published":"2020-05-22T14:55:13.000Z"},{"affected":"< 3.12.5; >= 4.0.0, < 4.3.4","affected_versions_present":true,"cve_id":"CVE-2020-11076","cve_url":"https://cve.blacktree.nl/cve/CVE-2020-11076","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-04T11:21:14.684Z","patch_url":"https://github.com/puma/puma/commit/f24d5521295a2152c286abb0a45a1e1e2bd275bd","primary_source":"","published":"2020-05-22T14:50:12.000Z"},{"affected":"< 3.12.4; >= 4.0.0, < 4.3.3","affected_versions_present":true,"cve_id":"CVE-2020-5249","cve_url":"https://cve.blacktree.nl/cve/CVE-2020-5249","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-04T08:22:09.092Z","patch_url":"https://github.com/puma/puma/commit/c22712fc93284a45a93f9ad7023888f3a65524f3","primary_source":"","published":"2020-03-02T15:20:21.000Z"},{"affected":"< 3.12.3; >= 4.0.0, < 4.3.2","affected_versions_present":true,"cve_id":"CVE-2020-5247","cve_url":"https://cve.blacktree.nl/cve/CVE-2020-5247","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-08-04T08:22:09.079Z","patch_url":"https://github.com/puma/puma/security/advisories/GHSA-84j7-475p-hp8v","primary_source":"","published":"2020-02-28T16:55:15.000Z"},{"affected":"< 4.3.1 < 4.3.1","affected_versions_present":true,"cve_id":"CVE-2019-16770","cve_url":"https://cve.blacktree.nl/cve/CVE-2019-16770","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-08-05T01:24:48.578Z","patch_url":"https://github.com/puma/puma/security/advisories/GHSA-7xx3-m584-x994","primary_source":"","published":"2019-12-05T19:35:14.000Z"}],"source_generated_at":"2026-10-07T06:21:30.017Z","vendor":"puma"}}
