sinatra
RubyGems6 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting sinatrapage 1 of 1
- CVE-2018-11627MEDIUMCVSS 6.1EG 6.1✓ Fixed in 2.0.22018-05-31
vulnerable: 2.0.0, 2.0.1, 2.0.1.rc1
Sinatra before 2.0.2 has XSS via the 400 Bad Request page that occurs upon a params parser exception.
- CVE-2018-7212MEDIUMCVSS 5.3EG 5.3✓ Fixed in 2.0.12018-02-18
vulnerable: 2.0.0 ... 2.0.1.rc1 (8 versions)
An issue was discovered in rack-protection/lib/rack/protection/path_traversal.rb in Sinatra 2.x before 2.0.1 on Windows. Path traversal is possible via backslash characters.
- CVE-2022-29970HIGHCVSS 7.5EG 7.5✓ Fixed in 2.2.02022-05-02
vulnerable: 0.1.0 ... 2.1.0 (88 versions)
Sinatra before 2.2.0 does not validate that the expanded path matches public_dir when serving static files.
- CVE-2022-45442HIGHCVSS 8.8EG 8.8✓ Fixed in 2.2.32022-11-28
vulnerable: 2.0.0 ... 2.2.2 (15 versions)
Sinatra is a domain-specific language for creating web applications in Ruby. An issue was discovered in Sinatra 2.0 before 2.2.3 and 3.0 before 3.0.4. An application is vulnerable to a reflected file download (RFD) attack that sets the Con…
- CVE-2024-21510MEDIUMCVSS 5.4EG 5.4✓ Fixed in 4.1.02024-11-01
vulnerable: 0.1.0 ... 4.0.1 (104 versions)
Versions of the package sinatra from 0.0.0 are vulnerable to Reliance on Untrusted Inputs in a Security Decision via the X-Forwarded-Host (XFH) header. When making a request to a method with redirect applied, it is possible to trigger an O…
- CVE-2025-61921HIGHCVSS 7.5EG 7.5✓ Fixed in 4.2.02025-10-10
vulnerable: 0.1.0 ... 4.1.1 (106 versions)
Sinatra is a domain-specific language for creating web applications in Ruby. In versions prior to 4.2.0, there is a denial of service vulnerability in the `If-Match` and `If-None-Match` header parsing component of Sinatra, if the `etag` me…
Check whether sinatra is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for sinatra CVEs against the assets you own.
Start Free Scan →