Skip to content

Commit 3c8e8b0

Browse files
committed
5.6.9 release note [ci skip]
1 parent 1293573 commit 3c8e8b0

File tree

1 file changed

+6
-1
lines changed

1 file changed

+6
-1
lines changed

History.md

+6-1
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,9 @@
1-
## 5.6.8 / 2023-01-08
1+
## 5.6.9 / 2024-09-19
2+
3+
* Security
4+
* Discards any headers using underscores if the non-underscore version also exists. Without this, an attacker could overwrite values set by intermediate proxies (e.g. X-Forwarded-For). ([CVE-2024-45614](https://github.com/puma/puma/security/advisories/GHSA-9hf4-67fc-4vf4)/GHSA-9hf4-67fc-4vf4)
5+
6+
## 5.6.8 / 2024-01-08
27

38
* Security
49
* Limit the size of chunk extensions. Without this limit, an attacker could cause unbounded resource (CPU, network bandwidth) consumption. ([GHSA-c2f4-cvqm-65w2](https://github.com/puma/puma/security/advisories/GHSA-c2f4-cvqm-65w2))

0 commit comments

Comments
 (0)