Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Phusion

First CVE: Sep 30, 2013Active for: 13 yearsTotal CVEs: 14
27.7
VTI Score
Low

Phusion's vulnerability footprint centers on application-server and messaging software such as Passenger and Juvia, components that sit in the deployment path of web applications and require careful access-control configuration. The recurring weakness classes—including permission misassignment, sensitive information exposure, link-following flaws, and race conditions—reflect the challenges of managing file resources and inter-process synchronization in multi-tenant or privilege-separated environments. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
14
Total CVEs
More Total CVEs than 94% of tracked vendors
1.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
6.2
Avg CVSS Score
Higher Avg CVSS Score than 36% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Phusion over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 30, 2013
12 years ago
Most Recent CVE
Feb 24, 2025
516 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (14 CVEs).

14 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-12026CRITICAL
During the spawning of a malicious Passenger-managed application, SpawningKit in Phusion Passenger 5.3.x before 5.3.2 allows such applications to replace key files or directories i
Jun 17, 20189.829NONO
CVE-2018-12027HIGH
An Insecure Permissions vulnerability in SpawningKit in Phusion Passenger 5.3.x before 5.3.2 causes information disclosure in the following situation: given a Passenger-spawned app
Jun 17, 20188.826NONO
CVE-2016-10345HIGH
In Phusion Passenger before 5.1.0, a known /tmp filename was used during passenger-install-nginx-module execution, which could allow local attackers to gain the privileges of the p
Apr 18, 20177.826NONO
CVE-2012-6135HIGH
RubyGems passenger 4.0.0 betas 1 and 2 allows remote attackers to delete arbitrary files during the startup process.
Nov 19, 20197.524NONO
CVE-2018-12028HIGH
An Incorrect Access Control vulnerability in SpawningKit in Phusion Passenger 5.3.x before 5.3.2 allows a Passenger-managed malicious application, upon spawning a child process, to
Jun 17, 20187.824NONO
CVE-2013-7134HIGH
Juvia uses the same secret key for all installations, which allows remote attackers to have unspecified impact by leveraging the secret key in app/config/initializers/secret_token.
Apr 29, 20147.524NONO
CVE-2025-26803HIGH
The http parser in Phusion Passenger 6.0.21 through 6.0.25 before 6.0.26 allows a denial of service during parsing of a request with an invalid HTTP method.
Feb 24, 20257.522NONO
CVE-2018-12029HIGH
A race condition in the nginx module in Phusion Passenger 3.x through 5.x before 5.3.2 allows local escalation of privileges when a non-standard passenger_instance_registry_dir wit
Jun 17, 20187.022NONO
CVE-2018-12615MEDIUM
An issue was discovered in switchGroup() in agent/ExecHelper/ExecHelperMain.cpp in Phusion Passenger before 5.3.2. The set of groups (gidset) is not set correctly, leaving it up to
Jun 21, 20185.319NONO
CVE-2013-2119MEDIUM
Phusion Passenger gem before 3.0.21 and 4.0.x before 4.0.5 for Ruby allows local users to cause a denial of service (prevent application start) or gain privileges by pre-creating a
Jan 3, 20144.619NONO
View all 14 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products14 CVEs
14%
29%
50%
Severity distribution among all CVEs352,708 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local4 (28.6%)
Network5 (35.7%)
Unknown5 (35.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (50.0%)
High2 (14.3%)
Unknown5 (35.7%)
User Interaction
None8 (57.1%)
Unknown5 (35.7%)
Required1 (7.1%)
Privileges Required
Low4 (28.6%)
High0 (0.0%)
None5 (35.7%)
Unknown5 (35.7%)

Exploit Exposure

Signals from CVEs in this vendor scope (14 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Phusion.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Phusion — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Phusion's Products

View all 2 CNAs →

Top CWEs