Phusion
14 known vulnerabilities
Top Products
The http parser in Phusion Passenger 6.0.21 through 6.0.25 before 6.0.26 allows a denial of service during parsing of a
RubyGems passenger 4.0.0 betas 1 and 2 allows remote attackers to delete arbitrary files during the startup process.
An issue was discovered in switchGroup() in agent/ExecHelper/ExecHelperMain.cpp in Phusion Passenger before 5.3.2. The s
A race condition in the nginx module in Phusion Passenger 3.x through 5.x before 5.3.2 allows local escalation of privil
An Incorrect Access Control vulnerability in SpawningKit in Phusion Passenger 5.3.x before 5.3.2 allows a Passenger-mana
An Insecure Permissions vulnerability in SpawningKit in Phusion Passenger 5.3.x before 5.3.2 causes information disclosu
During the spawning of a malicious Passenger-managed application, SpawningKit in Phusion Passenger 5.3.x before 5.3.2 al
In agent/Core/SpawningKit/Spawner.h in Phusion Passenger 5.1.10 (fixed in Passenger Open Source 5.1.11 and Passenger Ent
In Phusion Passenger before 5.1.0, a known /tmp filename was used during passenger-install-nginx-module execution, which
Frequently Asked Questions
How many CVEs affect Phusion?
Phusion has 14 CVE records in our database, including 1 critical and 6 high severity vulnerabilities.
What are the most severe Phusion vulnerabilities?
Phusion has 1 critical severity (CVSS 9.0+) and 6 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for Phusion vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Phusion products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Phusion Vulnerabilities
CyberStrike scans your infrastructure for Phusion vulnerabilities and provides real-time remediation guidance.
Get Started