sinatra
RubyGems6 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting sinatrapage 1 of 1
- CVE-2018-11627MEDIUMCVSS 6.1EG 6.1fixed in 2.0.22018-05-31
vulnerable: 2.0.0, 2.0.1, 2.0.1.rc1
Sinatra before 2.0.2 has XSS via the 400 Bad Request page that occurs upon a params parser exception.
- CVE-2018-7212MEDIUMCVSS 5.3EG 5.3fixed in 2.0.12018-02-18
vulnerable: 2.0.0 ... 2.0.1.rc1 (8 versions)
An issue was discovered in rack-protection/lib/rack/protection/path_traversal.rb in Sinatra 2.x before 2.0.1 on Windows. Path traversal is possible via backslash characters.
- CVE-2022-29970HIGHCVSS 7.5EG 7.5fixed in 2.2.02022-05-02
vulnerable: 0.1.0 ... 2.1.0 (88 versions)
Sinatra before 2.2.0 does not validate that the expanded path matches public_dir when serving static files.
- CVE-2022-45442HIGHCVSS 8.8EG 8.8fixed in 3.0.4 or 2.2.3, by version range2022-11-28
vulnerable: 2.0.0 ... 2.2.2 (15 versions)
Sinatra is a domain-specific language for creating web applications in Ruby. An issue was discovered in Sinatra 2.0 before 2.2.3 and 3.0 before 3.0.4. An application is vulnerable to a reflected file download (RFD) attack that sets the Con…
- CVE-2024-21510MEDIUMCVSS 5.4EG 5.4fixed in 4.1.02024-11-01
vulnerable: 0.1.0 ... 4.0.1 (104 versions)
Versions of the package sinatra from 0.0.0 are vulnerable to Reliance on Untrusted Inputs in a Security Decision via the X-Forwarded-Host (XFH) header. When making a request to a method with redirect applied, it is possible to trigger an O…
- CVE-2025-61921HIGHCVSS 7.5EG 7.5fixed in 4.2.02025-10-10
vulnerable: 0.1.0 ... 4.1.1 (106 versions)
Sinatra is a domain-specific language for creating web applications in Ruby. In versions prior to 4.2.0, there is a denial of service vulnerability in the `If-Match` and `If-None-Match` header parsing component of Sinatra, if the `etag` me…
Check whether sinatra is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for sinatra CVEs against the assets you own.
Book a Demo →