Products: 2
    Vulnerabilities: 14
    Known Exploited: 0
    1
    Critical Level Threats
    6
    High Level Threats
    5
    Medium Level Threats
    2
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2025-26803

    The http parser in Phusion Passenger 6.0.21 through 6.0.25 before 6.0.26 allows a denial of service during parsing of a request with an invalid HTTP method.

    Last Modified: Jul 13, 2025
    Published: Feb 24, 2025

    CVE-2018-12026

    passenger: SpawningKit allows malicious applications to replace files and directories allowing for arbitrary reads and writes

    Last Modified: Nov 21, 2024
    Published: Jun 05, 2018

    CVE-2018-12027

    passenger: Insecure permissions in SpawningKit can allow for redirection of traffic under certain configurations

    Last Modified: Nov 21, 2024
    Published: Jun 05, 2018

    CVE-2018-12028

    passenger: Improper access control in SpawningKit can allow malicious child processes to kill arbitrary processes

    Last Modified: Nov 21, 2024
    Published: Jun 05, 2018

    CVE-2018-12029

    passenger: CHMOD race condition in nginx_module/ngx_http_passenger_module.c allows for local privilege escalation

    Last Modified: Nov 21, 2024
    Published: Jun 05, 2018
    Items Per Page
    Phusion Vulnerabilities & Security CVEs | CVE-DB