Puppet Core 8.16.0

Released November 2025. This version of Puppet Core includes improvements to help prevent security vulnerabilities.

This version of Puppet Core will end of life (EOL) when it is superseded by the next release. Learn more about the Puppet Core platform lifecycle and EOL.

Security

Updated Thor gem

The Thor gem was updated to version 1.4.0 to address CVE-2025-54314. PA-7651

Updated curl

Curl was updated to version 8.16.0 to address CVE-2025-9086 and CVE-2025-10148. PA-7735

Updated REXML gem

REXML was updated to version 3.4.2 to address CVE-2025-58767. PA-7749

Updated OpenSSL

OpenSSL was updated to version 3.0.18 to CVE-2025-9230 and CVE-2025-9232. PA-7793

Patched URI gem

The URI gem in Puppet agent was patched to address CVE-2025-61594 . PA-7797