CVE-2016-9686: Puppet Enterprise
Medium severity, CVSS 5.3. EPSS: 1.3% chance of exploitation in the next 30 days.
The Puppet Communications Protocol (PCP) Broker incorrectly validates message header sizes. An attacker could use this to crash the PCP Broker, preventing commands from being sent to agents. This is resolved in Puppet Enterprise 2016.4.3 and 2016.5.2.
Affected products
- Puppet Puppet Enterprise: from 2016.4.0, before 2016.4.3 (fixed in 2016.4.3); version 2016.5.1 only
Published 2017-02-08. Last modified 2026-06-17.