Carrierwave is a Ruby-based file-upload and attachment-handling library widely embedded in web applications, where its role in processing user-supplied files creates an inherent injection and output-generation surface. The vendor's observed vulnerability pattern centers on input-neutralization and code-injection weaknesses including cross-site scripting, code injection, SSRF, and downstream injection, reflecting the parsing and rendering demands of file metadata and content handling. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Carrierwave Project over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-21305HIGH CarrierWave is an open-source RubyGem which provides a simple and flexible way to upload files from Ruby applications. In CarrierWave before versions 1.3.2 and 2.1.1, there is a co | Feb 8, 2021 | 8.8 | 32 | NO | NO |
CVE-2026-44587MEDIUM CarrierWave is a framework to upload files from Ruby applications. In versions prior to 2.2.7 and 3.1.3, the content_type_denylist check fails to escape regex metacharacters in str | Jun 16, 2026 | 6.1 | 24 | NO | NO |
CVE-2023-49090MEDIUM CarrierWave is a solution for file uploads for Rails, Sinatra and other Ruby web frameworks. CarrierWave has a Content-Type allowlist bypass vulnerability, possibly leading to XSS. | Nov 29, 2023 | 6.1 | 21 | NO | NO |
CVE-2024-29034MEDIUM CarrierWave is a solution for file uploads for Rails, Sinatra and other Ruby web frameworks. The vulnerability CVE-2023-49090 wasn't fully addressed. This vulnerability is caused b | Mar 24, 2024 | 6.1 | 20 | NO | NO |
CVE-2021-21288MEDIUM CarrierWave is an open-source RubyGem which provides a simple and flexible way to upload files from Ruby applications. In CarrierWave before versions 1.3.2 and 2.1.1 the download f | Feb 8, 2021 | 4.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Carrierwave Project.
Media articles that mention a CVE ID that affects a product developed by Carrierwave Project — matched by CVE ID, not by vendor name.