Known vulnerabilities in Phusion Passenger
Vendor:
Phusion B.V.
Software:
Phusion Passenger
Software CPE:
cpe:2.3:a:phusion_b_v:phusion_passenger:*:*:*:*:*:*:*:*
Website:
https://www.phusionpassenger.com/
Total vulnerabilities:
7
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
8.8
Breakdown by Severity Chart
6.1.8
6.1.7
6.1.6
6.1.5
6.1.4
6.1.3
6.1.2
6.1.1
6.1.0
6.0.27
6.0.26
6.0.25
6.0.24
6.0.23
6.0.22
6.0.21
6.0.20
6.0.19
6.0.18
6.0.17
6.0.16
6.0.15
6.0.14
6.0.13
6.0.12
6.0.11
6.0.10
6.0.9
6.0.8
6.0.7
6.0.6
6.0.5
6.0.4
6.0.3
enterprise-3.9.4
enterprise-3.9.5
enterprise-4.0.0
enterprise-5.0.0
3.9.4
3.9.5
request.handler.with.pipes
enterprise-5.1.2
enterprise-5.1.1
enterprise-5.1.0
enterprise-5.0.30
enterprise-5.0.29
enterprise-5.0.28
enterprise-5.0.27
enterprise-5.0.26
enterprise-5.0.25
enterprise-5.0.24
enterprise-5.0.23
enterprise-5.0.22
enterprise-5.0.21
enterprise-5.0.20
enterprise-5.0.18
enterprise-5.0.17
enterprise-5.0.16
enterprise-5.0.15
enterprise-5.0.14
enterprise-5.0.13
enterprise-5.0.12
enterprise-5.0.11
enterprise-5.0.10
enterprise-5.0.9
enterprise-5.0.8
enterprise-5.0.7
enterprise-5.0.6
enterprise-5.0.5
enterprise-5.0.4
enterprise-5.0.2
enterprise-5.0.1
enterprise-5.0.0.rc2
enterprise-5.0.0.rc1
enterprise-5.0.0.beta3
enterprise-5.0.0.beta2
enterprise-5.0.0.beta1
enterprise-4.0.60
enterprise-4.0.59
enterprise-4.0.58
enterprise-4.0.57
enterprise-4.0.56
enterprise-4.0.55
enterprise-4.0.54
enterprise-4.0.53
enterprise-4.0.52
enterprise-4.0.51
enterprise-4.0.50
enterprise-4.0.49
enterprise-4.0.48
enterprise-4.0.47
enterprise-4.0.46
enterprise-4.0.45
enterprise-4.0.44
enterprise-4.0.43
enterprise-4.0.42
enterprise-4.0.41
enterprise-4.0.40
enterprise-4.0.39
enterprise-4.0.38
enterprise-4.0.37
enterprise-4.0.36
enterprise-4.0.35
enterprise-4.0.33
enterprise-4.0.31
enterprise-4.0.30
enterprise-4.0.29
enterprise-4.0.28
enterprise-4.0.27
enterprise-4.0.26
enterprise-4.0.25
enterprise-4.0.24
enterprise-4.0.23
enterprise-4.0.22
enterprise-4.0.21
enterprise-4.0.20
enterprise-4.0.19
enterprise-4.0.18
enterprise-4.0.17
enterprise-4.0.16
enterprise-4.0.15
enterprise-4.0.14
enterprise-4.0.13
enterprise-4.0.12
enterprise-4.0.11
enterprise-4.0.10
enterprise-4.0.9
enterprise-4.0.8
enterprise-4.0.7
enterprise-4.0.6
enterprise-4.0.5
enterprise-4.0.4
enterprise-4.0.3
enterprise-4.0.2
enterprise-4.0.1
enterprise-4.0.0.rc7
enterprise-4.0.0.rc6
enterprise-4.0.0.rc5
enterprise-4.0.0.rc4
enterprise-3.9.5.rc3
enterprise-3.9.4.rc2
enterprise-3.9.3
enterprise-3.9.2.beta
enterprise-3.9.1.beta
enterprise-3.9.0.beta
enterprise-3.0.21
enterprise-3.0.20
enterprise-3.0.19
enterprise-3.0.18
enterprise-3.0.17
enterprise-3.0.16
enterprise-3.0.15
5.1.12
5.1.11
5.1.10
5.1.9
5.1.8
5.0.0.rc2
5.0.0.rc1
5.0.0.beta3
5.0.0.beta2
5.0.0.beta1
4.0.0.rc6
4.0.0.rc4
3.9.5.rc3
3.9.4.rc2
3.9.3.rc1
3.9.2.beta
3.9.1.beta
3.9.0.beta
3.0.0.rc1
3.0.0.pre3
3.0.0.pre2
3.0.0.pre1
2.2.15
2.2.14
2.2.13
2.2.12
2.2.11
2.2.10
2.2.9
2.2.8
2.2.7
2.2.6
2.2.5
2.2.4
2.2.3
2.2.2
2.2.1
2.2.0
2.1.3
2.1.2
2.1.1
2.0.6
2.0.5
2.0.4
2.0.3
2.0.2
2.0.1
1.9.1
1.9.0
1.0.5
1.0.4
1.0.3
1.0.2
1.0.1
1.0.0
6.0.2
6.0.1
6.0.0
5.3.7
5.3.6
5.3.5
5.3.4
5.3.3
3.9.3
3.9.0
3.0.21
3.0.20
3.0.19
3.0.18
3.0.17
3.0.16
3.0.15
3.0.14
3.0.13
3.0.12
3.0.11
3.0.10
3.0.9
3.0.8
3.0.7
3.0.6
3.0.5
3.0.4
3.0.3
3.0.2
3.0.1
3.0.0
5.2.3
5.2.2
5.2.1
5.2.0
5.3.2
5.3.1
5.3.0
5.1.7
5.1.6
5.1.5
5.1.4
5.1.3
5.1.2
5.1.1
5.1.0
5.0.30
5.0.29
5.0.28
5.0.27
5.0.26
5.0.25
5.0.24
5.0.23
5.0.22
5.0.21
5.0.20
5.0.19
5.0.18
5.0.17
5.0.16
5.0.15
5.0.14
5.0.13
5.0.12
5.0.11
5.0.10
5.0.9
5.0.8
5.0.7
5.0.6
5.0.5
5.0.4
5.0.3
5.0.2
5.0.1
5.0.0
4.0.60
4.0.59
4.0.58
4.0.57
4.0.56
4.0.55
4.0.54
4.0.53
4.0.52
4.0.51
4.0.50
4.0.49
4.0.48
4.0.47
4.0.46
4.0.45
4.0.44
4.0.43
4.0.42
4.0.41
4.0.40
4.0.39
4.0.38
4.0.37
4.0.36
4.0.35
4.0.34
4.0.33
4.0.32
4.0.31
4.0.30
4.0.29
4.0.28
4.0.27
4.0.26
4.0.25
4.0.24
4.0.23
4.0.22
4.0.21
4.0.20
4.0.19
4.0.18
4.0.17
4.0.16
4.0.15
4.0.14
4.0.13
4.0.10
4.0.8
4.0.7
4.0.6
4.0.5
4.0.4
4.0.3
4.0.2
4.0.1
4.0.0
Vulnerabilities (7)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU104968 - Improper input validation CVE-2025-26803 |
CWE-20 | Medium | 6.0.26 | 27.02.2025 |
SB2025022767 SB2025022772 |
||
| #VU18066 - UNIX Symbolic Link (Symlink) Following CVE-2017-16355 |
CWE-61 | Low | 5.1.11 | 25.03.2019 |
SB2017121449 SB2019032502 |
||
| #VU13991 - Improper Access Control CVE-2018-12028 |
CWE-284 | Low | 5.3.2 | 24.07.2018 |
SB2018072402 SB2018072403 |
||
| #VU13990 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') CVE-2018-12029 |
CWE-362 | Low | 5.3.2 | 24.07.2018 |
SB2018072402 SB2018072403 |
||
| #VU13989 - Permissions, Privileges, and Access Controls CVE-2018-12026 |
CWE-264 | Low | 5.3.2 | 24.07.2018 |
SB2018072402 SB2018072403 |
||
| #VU13988 - Exposure of sensitive information to an unauthorized actor CVE-2018-12027 |
CWE-200 | Low | 5.3.2 | 23.07.2018 |
SB2018072402 SB2018072403 |
||
| #VU40538 - Improper input validation CVE-2015-7519 |
CWE-20 | Low | - | 08.01.2016 |
SB2016010802 |