Phusionpassenger is an application server and process manager for Ruby, Python, and Node.js applications, deployed in production environments where it handles request processing and resource allocation. The vendor's vulnerability history centers on improper input validation in its request handling and configuration parsing, reflecting the complexity of safely processing external inputs in a deployment-critical component. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Phusionpassenger over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
agent/Core/Controller/SendRequest.cpp in Phusion Passenger before 4.0.60 and 5.0.x before 5.0.22, when used in Apache integration mode or in standalone mode without a filtering pro | Jan 8, 2016 | 3.7 | 13 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Phusionpassenger.
Media articles that mention a CVE ID that affects a product developed by Phusionpassenger — matched by CVE ID, not by vendor name.