Sinatra is a lightweight web-application framework for Ruby whose vulnerability profile, despite modest disclosure volume, reflects its role in building web services and its exposure to input-handling and path-validation risks. The recurring issues cluster around path traversal, unsafe code downloads, cross-site scripting, regular-expression denial-of-service, and information disclosure—weakness classes typical of web frameworks where user input flows through routing, templating, and static-file serving. Defenders should apply updates to this framework and its companion Rack middleware systematically, as these classes of flaws carry lasting attack surface; live severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sinatrarb over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-45442HIGH Sinatra is a domain-specific language for creating web applications in Ruby. An issue was discovered in Sinatra 2.0 before 2.2.3 and 3.0 before 3.0.4. An application is vulnerable | Nov 28, 2022 | 8.8 | 28 | NO | NO |
CVE-2025-61921HIGH Sinatra is a domain-specific language for creating web applications in Ruby. In versions prior to 4.2.0, there is a denial of service vulnerability in the `If-Match` and `If-None-M | Oct 10, 2025 | 7.5 | 26 | NO | NO |
CVE-2022-29970HIGH Sinatra before 2.2.0 does not validate that the expanded path matches public_dir when serving static files. | May 2, 2022 | 7.5 | 26 | NO | NO |
CVE-2018-1000119MEDIUM Sinatra rack-protection versions 1.5.4 and 2.0.0.rc3 and earlier contains a timing attack vulnerability in the CSRF token checking that can result in signatures can be exposed. Thi | Mar 7, 2018 | 5.9 | 22 | NO | NO |
CVE-2018-11627MEDIUM Sinatra before 2.0.2 has XSS via the 400 Bad Request page that occurs upon a params parser exception. | May 31, 2018 | 6.1 | 21 | NO | NO |
CVE-2018-7212MEDIUM An issue was discovered in rack-protection/lib/rack/protection/path_traversal.rb in Sinatra 2.x before 2.0.1 on Windows. Path traversal is possible via backslash characters. | Feb 18, 2018 | 5.3 | 20 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sinatrarb.
Media articles that mention a CVE ID that affects a product developed by Sinatrarb — matched by CVE ID, not by vendor name.