Product:

Passenger

(Phusion)
Repositories https://github.com/phusion/passenger
#Vulnerabilities 13
Date Id Summary Products Score Patch Annotated
2025-02-24 CVE-2025-26803 The http parser in Phusion Passenger 6.0.21 through 6.0.25 before 6.0.26 allows a denial of service during parsing of a request with an invalid HTTP method. Passenger 7.5
2014-01-03 CVE-2013-2119 Phusion Passenger gem before 3.0.21 and 4.0.x before 4.0.5 for Ruby allows local users to cause a denial of service (prevent application start) or gain privileges by pre-creating a temporary "config" file in a directory with a predictable name in /tmp/ before it is used by the gem. Passenger, Openshift N/A
2019-11-19 CVE-2012-6135 RubyGems passenger 4.0.0 betas 1 and 2 allows remote attackers to delete arbitrary files during the startup process. Passenger, Openshift N/A