Phusion's vulnerability footprint centers on application-server and messaging software such as Passenger and Juvia, components that sit in the deployment path of web applications and require careful access-control configuration. The recurring weakness classes—including permission misassignment, sensitive information exposure, link-following flaws, and race conditions—reflect the challenges of managing file resources and inter-process synchronization in multi-tenant or privilege-separated environments. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Phusion over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-12026CRITICAL During the spawning of a malicious Passenger-managed application, SpawningKit in Phusion Passenger 5.3.x before 5.3.2 allows such applications to replace key files or directories i | Jun 17, 2018 | 9.8 | 29 | NO | NO |
CVE-2018-12027HIGH An Insecure Permissions vulnerability in SpawningKit in Phusion Passenger 5.3.x before 5.3.2 causes information disclosure in the following situation: given a Passenger-spawned app | Jun 17, 2018 | 8.8 | 26 | NO | NO |
CVE-2016-10345HIGH In Phusion Passenger before 5.1.0, a known /tmp filename was used during passenger-install-nginx-module execution, which could allow local attackers to gain the privileges of the p | Apr 18, 2017 | 7.8 | 26 | NO | NO |
CVE-2012-6135HIGH RubyGems passenger 4.0.0 betas 1 and 2 allows remote attackers to delete arbitrary files during the startup process. | Nov 19, 2019 | 7.5 | 24 | NO | NO |
CVE-2018-12028HIGH An Incorrect Access Control vulnerability in SpawningKit in Phusion Passenger 5.3.x before 5.3.2 allows a Passenger-managed malicious application, upon spawning a child process, to | Jun 17, 2018 | 7.8 | 24 | NO | NO |
CVE-2013-7134HIGH Juvia uses the same secret key for all installations, which allows remote attackers to have unspecified impact by leveraging the secret key in app/config/initializers/secret_token. | Apr 29, 2014 | 7.5 | 24 | NO | NO |
CVE-2025-26803HIGH The http parser in Phusion Passenger 6.0.21 through 6.0.25 before 6.0.26 allows a denial of service during parsing of a request with an invalid HTTP method. | Feb 24, 2025 | 7.5 | 22 | NO | NO |
CVE-2018-12029HIGH A race condition in the nginx module in Phusion Passenger 3.x through 5.x before 5.3.2 allows local escalation of privileges when a non-standard passenger_instance_registry_dir wit | Jun 17, 2018 | 7.0 | 22 | NO | NO |
CVE-2018-12615MEDIUM An issue was discovered in switchGroup() in agent/ExecHelper/ExecHelperMain.cpp in Phusion Passenger before 5.3.2. The set of groups (gidset) is not set correctly, leaving it up to | Jun 21, 2018 | 5.3 | 19 | NO | NO |
CVE-2013-2119MEDIUM Phusion Passenger gem before 3.0.21 and 4.0.x before 4.0.5 for Ruby allows local users to cause a denial of service (prevent application start) or gain privileges by pre-creating a | Jan 3, 2014 | 4.6 | 19 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Phusion.
Media articles that mention a CVE ID that affects a product developed by Phusion — matched by CVE ID, not by vendor name.