← Back

Sinatrarb

sinatrarb

6 CVEs • 2 products

Products (2)

Click to collapse
Toggle
Sinatra
sinatra

CVEs (6)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Sinatrarb
1Sinatra
Jun 17, 2026
Oct 10, 2025
2.7 LOW· v4
7.5 HIGH· v3
N/A· v2
Sinatra is a domain-specific language for creating web applications in Ruby. In versions prior to 4.2.0, there is a denial of service vulnerability in the `If-Match` and `If-None-Match` header parsing component of Sinatr...Show more
Sinatra is a domain-specific language for creating web applications in Ruby. In versions prior to 4.2.0, there is a denial of service vulnerability in the `If-Match` and `If-None-Match` header parsing component of Sinatra, if the `etag` method is used when constructing the response. Carefully crafted input can cause `If-Match` and `If-None-Match` header parsing in Sinatra to take an unexpected amount of time, possibly resulting in a denial of service attack vector. This header is typically involved in generating the `ETag` header value. Any applications that use the `etag` method when generating a response are impacted. Version 4.2.0 fixes the issue.Show less
2Debian
Sinatrarb
2Debian Linux
Sinatra
Jun 17, 2026
Nov 28, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
Sinatra is a domain-specific language for creating web applications in Ruby. An issue was discovered in Sinatra 2.0 before 2.2.3 and 3.0 before 3.0.4. An application is vulnerable to a reflected file download (RFD) attac...Show more
Sinatra is a domain-specific language for creating web applications in Ruby. An issue was discovered in Sinatra 2.0 before 2.2.3 and 3.0 before 3.0.4. An application is vulnerable to a reflected file download (RFD) attack that sets the Content-Disposition header of a response when the filename is derived from user-supplied input. Version 2.2.3 and 3.0.4 contain patches for this issue.Show less
2Debian
Sinatrarb
2Debian Linux
Sinatra
Jun 17, 2026
May 2, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Sinatra before 2.2.0 does not validate that the expanded path matches public_dir when serving static files.
2Redhat
Sinatrarb
2Cloudforms
Sinatra
Nov 21, 2024
May 31, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Sinatra before 2.0.2 has XSS via the 400 Bad Request page that occurs upon a params parser exception.
1Sinatrarb
1Rack Protection
Nov 21, 2024
Mar 7, 2018
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Sinatra rack-protection versions 1.5.4 and 2.0.0.rc3 and earlier contains a timing attack vulnerability in the CSRF token checking that can result in signatures can be exposed. This attack appear to be exploitable via ne...Show more
Sinatra rack-protection versions 1.5.4 and 2.0.0.rc3 and earlier contains a timing attack vulnerability in the CSRF token checking that can result in signatures can be exposed. This attack appear to be exploitable via network connectivity to the ruby application. This vulnerability appears to have been fixed in 1.5.5 and 2.0.0.Show less
1Sinatrarb
1Sinatra
Jun 17, 2026
Feb 18, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An issue was discovered in rack-protection/lib/rack/protection/path_traversal.rb in Sinatra 2.x before 2.0.1 on Windows. Path traversal is possible via backslash characters.