Package
logstash-9.4-iamguarded-compat
Component
puma
Latest update
Fixed version
9.4.4-r0
7.5
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Fixed version
9.4.4-r0Status
Impact
The vulnerable puma component is pulled in transitively and constrained to the 6.x release line by the application's own dependency requirements. The fix for CVE-2026-47736 is only available in puma 7.2.1 and later, which is incompatible with that constraint, so the patched version cannot be adopted until a future upstream release relaxes the requirement.
Status