shrine
Shrine is a toolkit for file attachments in Ruby applications. It supports uploading, downloading, processing and deleting IO objects, backed by various storage engines. It uses efficient streaming for low memory usage. Shrine comes with a high-level interface for attaching uploaded files to database records, saving their location and metadata to a database column, and tying them to record's lifecycle. It natively supports background jobs and direct uploads for fully asynchronous user experience.
Activity
- Latest release
- 2mo ago
- Total releases
- 59
- Cadence
- ~25 days
- Last 12 months
- 4
Reach
- Stars
- —
Details
- License
- MIT
- First release
- Oct 25, 2015
| Version | Released | |
|---|---|---|
3.9.0
minor
|
3.9.0
minor
Dependencies (25)
+ 17 more
Changelog
Compare changes
|
|
3.8.0
minor
|
3.8.0
minor
Dependencies (22)
+ 14 more
Changelog
Compare changes
|
|
3.7.1
patch
|
3.7.1
patch
Dependencies (24)
+ 16 more
Changelog
Compare changes
|
|
3.7.0
minor
|
3.7.0
minor
Dependencies (24)
+ 16 more
Changelog
Compare changes
|
|
3.6.0
minor
|
3.6.0
minor
Dependencies (24)
+ 16 more
Changelog
Compare changes
|
|
3.5.0
minor
|
3.5.0
minor
Dependencies (24)
+ 16 more
Changelog
Compare changes
|
|
3.4.0
minor
|
3.4.0
minor
Dependencies (24)
+ 16 more
Changelog
Compare changes
|
|
3.3.0
minor
|
3.3.0
minor
Dependencies (23)
+ 15 more
Changelog
Compare changes
|
|
3.2.2
patch
1 CVE
CVE-2020-15237
GHSA-5jjv-x4fq-qjwp
Oct 05, 2020
Possible timing attack in derivation_endpoint
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
ImpactWhen using the PatchesThe problem has been fixed by comparing sent and calculated signature in constant time, using WorkaroundsUsers of older Shrine versions can apply the following monkey-patch after loading the
ReferencesYou can read more about timing attacks here. Affected versions
0.9.0
1.0.0
1.1.0
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.1.0
2.1.1
+ 39 more Show less
2.10.0
2.10.1
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.17.1
2.18.0
2.18.1
2.19.0
2.19.1
2.19.2
2.19.3
2.19.4
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.9.0
3.0.0
3.0.0.alpha
3.0.0.beta
3.0.0.beta2
3.0.0.beta3
3.0.0.rc
3.0.1
3.1.0
3.2.0
3.2.1
3.2.2
Fixed in
3.3.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
3.2.2
patch
Dependencies (23)
+ 15 more
Changelog
Compare changes
|
|
2.19.4
patch
1 CVE
CVE-2020-15237
GHSA-5jjv-x4fq-qjwp
Oct 05, 2020
Possible timing attack in derivation_endpoint
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
ImpactWhen using the PatchesThe problem has been fixed by comparing sent and calculated signature in constant time, using WorkaroundsUsers of older Shrine versions can apply the following monkey-patch after loading the
ReferencesYou can read more about timing attacks here. Affected versions
0.9.0
1.0.0
1.1.0
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.1.0
2.1.1
+ 39 more Show less
2.10.0
2.10.1
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.17.1
2.18.0
2.18.1
2.19.0
2.19.1
2.19.2
2.19.3
2.19.4
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.9.0
3.0.0
3.0.0.alpha
3.0.0.beta
3.0.0.beta2
3.0.0.beta3
3.0.0.rc
3.0.1
3.1.0
3.2.0
3.2.1
3.2.2
Fixed in
3.3.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
2.19.4
patch
Dependencies (25)
+ 17 more
Changelog
Compare changes
|
|
3.2.1
patch
1 CVE
CVE-2020-15237
GHSA-5jjv-x4fq-qjwp
Oct 05, 2020
Possible timing attack in derivation_endpoint
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
ImpactWhen using the PatchesThe problem has been fixed by comparing sent and calculated signature in constant time, using WorkaroundsUsers of older Shrine versions can apply the following monkey-patch after loading the
ReferencesYou can read more about timing attacks here. Affected versions
0.9.0
1.0.0
1.1.0
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.1.0
2.1.1
+ 39 more Show less
2.10.0
2.10.1
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.17.1
2.18.0
2.18.1
2.19.0
2.19.1
2.19.2
2.19.3
2.19.4
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.9.0
3.0.0
3.0.0.alpha
3.0.0.beta
3.0.0.beta2
3.0.0.beta3
3.0.0.rc
3.0.1
3.1.0
3.2.0
3.2.1
3.2.2
Fixed in
3.3.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
3.2.1
patch
Dependencies (23)
+ 15 more
Changelog
Compare changes
|
|
3.2.0
minor
1 CVE
CVE-2020-15237
GHSA-5jjv-x4fq-qjwp
Oct 05, 2020
Possible timing attack in derivation_endpoint
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
ImpactWhen using the PatchesThe problem has been fixed by comparing sent and calculated signature in constant time, using WorkaroundsUsers of older Shrine versions can apply the following monkey-patch after loading the
ReferencesYou can read more about timing attacks here. Affected versions
0.9.0
1.0.0
1.1.0
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.1.0
2.1.1
+ 39 more Show less
2.10.0
2.10.1
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.17.1
2.18.0
2.18.1
2.19.0
2.19.1
2.19.2
2.19.3
2.19.4
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.9.0
3.0.0
3.0.0.alpha
3.0.0.beta
3.0.0.beta2
3.0.0.beta3
3.0.0.rc
3.0.1
3.1.0
3.2.0
3.2.1
3.2.2
Fixed in
3.3.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
3.2.0
minor
Dependencies (24)
+ 16 more
Changelog
Compare changes
|
|
3.1.0
minor
1 CVE
CVE-2020-15237
GHSA-5jjv-x4fq-qjwp
Oct 05, 2020
Possible timing attack in derivation_endpoint
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
ImpactWhen using the PatchesThe problem has been fixed by comparing sent and calculated signature in constant time, using WorkaroundsUsers of older Shrine versions can apply the following monkey-patch after loading the
ReferencesYou can read more about timing attacks here. Affected versions
0.9.0
1.0.0
1.1.0
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.1.0
2.1.1
+ 39 more Show less
2.10.0
2.10.1
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.17.1
2.18.0
2.18.1
2.19.0
2.19.1
2.19.2
2.19.3
2.19.4
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.9.0
3.0.0
3.0.0.alpha
3.0.0.beta
3.0.0.beta2
3.0.0.beta3
3.0.0.rc
3.0.1
3.1.0
3.2.0
3.2.1
3.2.2
Fixed in
3.3.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
3.1.0
minor
Dependencies (24)
+ 16 more
Changelog
Compare changes
|
|
3.0.1
patch
1 CVE
CVE-2020-15237
GHSA-5jjv-x4fq-qjwp
Oct 05, 2020
Possible timing attack in derivation_endpoint
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
ImpactWhen using the PatchesThe problem has been fixed by comparing sent and calculated signature in constant time, using WorkaroundsUsers of older Shrine versions can apply the following monkey-patch after loading the
ReferencesYou can read more about timing attacks here. Affected versions
0.9.0
1.0.0
1.1.0
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.1.0
2.1.1
+ 39 more Show less
2.10.0
2.10.1
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.17.1
2.18.0
2.18.1
2.19.0
2.19.1
2.19.2
2.19.3
2.19.4
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.9.0
3.0.0
3.0.0.alpha
3.0.0.beta
3.0.0.beta2
3.0.0.beta3
3.0.0.rc
3.0.1
3.1.0
3.2.0
3.2.1
3.2.2
Fixed in
3.3.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
3.0.1
patch
Dependencies (24)
+ 16 more
Changelog
Compare changes
|
|
3.0.0
major
1 CVE
CVE-2020-15237
GHSA-5jjv-x4fq-qjwp
Oct 05, 2020
Possible timing attack in derivation_endpoint
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
ImpactWhen using the PatchesThe problem has been fixed by comparing sent and calculated signature in constant time, using WorkaroundsUsers of older Shrine versions can apply the following monkey-patch after loading the
ReferencesYou can read more about timing attacks here. Affected versions
0.9.0
1.0.0
1.1.0
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.1.0
2.1.1
+ 39 more Show less
2.10.0
2.10.1
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.17.1
2.18.0
2.18.1
2.19.0
2.19.1
2.19.2
2.19.3
2.19.4
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.9.0
3.0.0
3.0.0.alpha
3.0.0.beta
3.0.0.beta2
3.0.0.beta3
3.0.0.rc
3.0.1
3.1.0
3.2.0
3.2.1
3.2.2
Fixed in
3.3.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
3.0.0
major
Dependencies (24)
+ 16 more
Changelog
Compare changes
|
|
3.0.0.rc
pre
1 CVE
CVE-2020-15237
GHSA-5jjv-x4fq-qjwp
Oct 05, 2020
Possible timing attack in derivation_endpoint
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
ImpactWhen using the PatchesThe problem has been fixed by comparing sent and calculated signature in constant time, using WorkaroundsUsers of older Shrine versions can apply the following monkey-patch after loading the
ReferencesYou can read more about timing attacks here. Affected versions
0.9.0
1.0.0
1.1.0
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.1.0
2.1.1
+ 39 more Show less
2.10.0
2.10.1
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.17.1
2.18.0
2.18.1
2.19.0
2.19.1
2.19.2
2.19.3
2.19.4
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.9.0
3.0.0
3.0.0.alpha
3.0.0.beta
3.0.0.beta2
3.0.0.beta3
3.0.0.rc
3.0.1
3.1.0
3.2.0
3.2.1
3.2.2
Fixed in
3.3.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
3.0.0.rc
pre
Dependencies (24)
+ 16 more
Changelog
Compare changes
|
|
3.0.0.beta3
pre
1 CVE
CVE-2020-15237
GHSA-5jjv-x4fq-qjwp
Oct 05, 2020
Possible timing attack in derivation_endpoint
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
ImpactWhen using the PatchesThe problem has been fixed by comparing sent and calculated signature in constant time, using WorkaroundsUsers of older Shrine versions can apply the following monkey-patch after loading the
ReferencesYou can read more about timing attacks here. Affected versions
0.9.0
1.0.0
1.1.0
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.1.0
2.1.1
+ 39 more Show less
2.10.0
2.10.1
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.17.1
2.18.0
2.18.1
2.19.0
2.19.1
2.19.2
2.19.3
2.19.4
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.9.0
3.0.0
3.0.0.alpha
3.0.0.beta
3.0.0.beta2
3.0.0.beta3
3.0.0.rc
3.0.1
3.1.0
3.2.0
3.2.1
3.2.2
Fixed in
3.3.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
3.0.0.beta3
pre
Dependencies (24)
+ 16 more
Changelog
Compare changes
|
|
3.0.0.beta2
pre
1 CVE
CVE-2020-15237
GHSA-5jjv-x4fq-qjwp
Oct 05, 2020
Possible timing attack in derivation_endpoint
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
ImpactWhen using the PatchesThe problem has been fixed by comparing sent and calculated signature in constant time, using WorkaroundsUsers of older Shrine versions can apply the following monkey-patch after loading the
ReferencesYou can read more about timing attacks here. Affected versions
0.9.0
1.0.0
1.1.0
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.1.0
2.1.1
+ 39 more Show less
2.10.0
2.10.1
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.17.1
2.18.0
2.18.1
2.19.0
2.19.1
2.19.2
2.19.3
2.19.4
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.9.0
3.0.0
3.0.0.alpha
3.0.0.beta
3.0.0.beta2
3.0.0.beta3
3.0.0.rc
3.0.1
3.1.0
3.2.0
3.2.1
3.2.2
Fixed in
3.3.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
3.0.0.beta2
pre
Dependencies (24)
+ 16 more
Changelog
Compare changes
|
|
3.0.0.beta
pre
1 CVE
CVE-2020-15237
GHSA-5jjv-x4fq-qjwp
Oct 05, 2020
Possible timing attack in derivation_endpoint
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
ImpactWhen using the PatchesThe problem has been fixed by comparing sent and calculated signature in constant time, using WorkaroundsUsers of older Shrine versions can apply the following monkey-patch after loading the
ReferencesYou can read more about timing attacks here. Affected versions
0.9.0
1.0.0
1.1.0
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.1.0
2.1.1
+ 39 more Show less
2.10.0
2.10.1
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.17.1
2.18.0
2.18.1
2.19.0
2.19.1
2.19.2
2.19.3
2.19.4
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.9.0
3.0.0
3.0.0.alpha
3.0.0.beta
3.0.0.beta2
3.0.0.beta3
3.0.0.rc
3.0.1
3.1.0
3.2.0
3.2.1
3.2.2
Fixed in
3.3.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
3.0.0.beta
pre
Dependencies (24)
+ 16 more
Changelog
Compare changes
|
|
3.0.0.alpha
pre
1 CVE
CVE-2020-15237
GHSA-5jjv-x4fq-qjwp
Oct 05, 2020
Possible timing attack in derivation_endpoint
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
ImpactWhen using the PatchesThe problem has been fixed by comparing sent and calculated signature in constant time, using WorkaroundsUsers of older Shrine versions can apply the following monkey-patch after loading the
ReferencesYou can read more about timing attacks here. Affected versions
0.9.0
1.0.0
1.1.0
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.1.0
2.1.1
+ 39 more Show less
2.10.0
2.10.1
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.17.1
2.18.0
2.18.1
2.19.0
2.19.1
2.19.2
2.19.3
2.19.4
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.9.0
3.0.0
3.0.0.alpha
3.0.0.beta
3.0.0.beta2
3.0.0.beta3
3.0.0.rc
3.0.1
3.1.0
3.2.0
3.2.1
3.2.2
Fixed in
3.3.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
3.0.0.alpha
pre
Dependencies (24)
+ 16 more
Changelog
Compare changes
|
|
2.19.3
patch
1 CVE
CVE-2020-15237
GHSA-5jjv-x4fq-qjwp
Oct 05, 2020
Possible timing attack in derivation_endpoint
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
ImpactWhen using the PatchesThe problem has been fixed by comparing sent and calculated signature in constant time, using WorkaroundsUsers of older Shrine versions can apply the following monkey-patch after loading the
ReferencesYou can read more about timing attacks here. Affected versions
0.9.0
1.0.0
1.1.0
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.1.0
2.1.1
+ 39 more Show less
2.10.0
2.10.1
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.17.1
2.18.0
2.18.1
2.19.0
2.19.1
2.19.2
2.19.3
2.19.4
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.9.0
3.0.0
3.0.0.alpha
3.0.0.beta
3.0.0.beta2
3.0.0.beta3
3.0.0.rc
3.0.1
3.1.0
3.2.0
3.2.1
3.2.2
Fixed in
3.3.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
2.19.3
patch
Dependencies (25)
+ 17 more
Changelog
Compare changes
|
|
2.19.2
patch
1 CVE
CVE-2020-15237
GHSA-5jjv-x4fq-qjwp
Oct 05, 2020
Possible timing attack in derivation_endpoint
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
ImpactWhen using the PatchesThe problem has been fixed by comparing sent and calculated signature in constant time, using WorkaroundsUsers of older Shrine versions can apply the following monkey-patch after loading the
ReferencesYou can read more about timing attacks here. Affected versions
0.9.0
1.0.0
1.1.0
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.1.0
2.1.1
+ 39 more Show less
2.10.0
2.10.1
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.17.1
2.18.0
2.18.1
2.19.0
2.19.1
2.19.2
2.19.3
2.19.4
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.9.0
3.0.0
3.0.0.alpha
3.0.0.beta
3.0.0.beta2
3.0.0.beta3
3.0.0.rc
3.0.1
3.1.0
3.2.0
3.2.1
3.2.2
Fixed in
3.3.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
2.19.2
patch
Dependencies (25)
+ 17 more
Changelog
Compare changes
|
|
2.19.1
patch
1 CVE
CVE-2020-15237
GHSA-5jjv-x4fq-qjwp
Oct 05, 2020
Possible timing attack in derivation_endpoint
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
ImpactWhen using the PatchesThe problem has been fixed by comparing sent and calculated signature in constant time, using WorkaroundsUsers of older Shrine versions can apply the following monkey-patch after loading the
ReferencesYou can read more about timing attacks here. Affected versions
0.9.0
1.0.0
1.1.0
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.1.0
2.1.1
+ 39 more Show less
2.10.0
2.10.1
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.17.1
2.18.0
2.18.1
2.19.0
2.19.1
2.19.2
2.19.3
2.19.4
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.9.0
3.0.0
3.0.0.alpha
3.0.0.beta
3.0.0.beta2
3.0.0.beta3
3.0.0.rc
3.0.1
3.1.0
3.2.0
3.2.1
3.2.2
Fixed in
3.3.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
2.19.1
patch
Dependencies (25)
+ 17 more
Changelog
Compare changes
|
|
2.19.0
minor
1 CVE
CVE-2020-15237
GHSA-5jjv-x4fq-qjwp
Oct 05, 2020
Possible timing attack in derivation_endpoint
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
ImpactWhen using the PatchesThe problem has been fixed by comparing sent and calculated signature in constant time, using WorkaroundsUsers of older Shrine versions can apply the following monkey-patch after loading the
ReferencesYou can read more about timing attacks here. Affected versions
0.9.0
1.0.0
1.1.0
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.1.0
2.1.1
+ 39 more Show less
2.10.0
2.10.1
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.17.1
2.18.0
2.18.1
2.19.0
2.19.1
2.19.2
2.19.3
2.19.4
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.9.0
3.0.0
3.0.0.alpha
3.0.0.beta
3.0.0.beta2
3.0.0.beta3
3.0.0.rc
3.0.1
3.1.0
3.2.0
3.2.1
3.2.2
Fixed in
3.3.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
2.19.0
minor
Dependencies (25)
+ 17 more
Changelog
Compare changes
|
|
2.18.1
patch
1 CVE
CVE-2020-15237
GHSA-5jjv-x4fq-qjwp
Oct 05, 2020
Possible timing attack in derivation_endpoint
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
ImpactWhen using the PatchesThe problem has been fixed by comparing sent and calculated signature in constant time, using WorkaroundsUsers of older Shrine versions can apply the following monkey-patch after loading the
ReferencesYou can read more about timing attacks here. Affected versions
0.9.0
1.0.0
1.1.0
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.1.0
2.1.1
+ 39 more Show less
2.10.0
2.10.1
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.17.1
2.18.0
2.18.1
2.19.0
2.19.1
2.19.2
2.19.3
2.19.4
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.9.0
3.0.0
3.0.0.alpha
3.0.0.beta
3.0.0.beta2
3.0.0.beta3
3.0.0.rc
3.0.1
3.1.0
3.2.0
3.2.1
3.2.2
Fixed in
3.3.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
2.18.1
patch
Dependencies (23)
+ 15 more
Changelog
Compare changes
|
|
2.18.0
minor
1 CVE
CVE-2020-15237
GHSA-5jjv-x4fq-qjwp
Oct 05, 2020
Possible timing attack in derivation_endpoint
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
ImpactWhen using the PatchesThe problem has been fixed by comparing sent and calculated signature in constant time, using WorkaroundsUsers of older Shrine versions can apply the following monkey-patch after loading the
ReferencesYou can read more about timing attacks here. Affected versions
0.9.0
1.0.0
1.1.0
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.1.0
2.1.1
+ 39 more Show less
2.10.0
2.10.1
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.17.1
2.18.0
2.18.1
2.19.0
2.19.1
2.19.2
2.19.3
2.19.4
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.9.0
3.0.0
3.0.0.alpha
3.0.0.beta
3.0.0.beta2
3.0.0.beta3
3.0.0.rc
3.0.1
3.1.0
3.2.0
3.2.1
3.2.2
Fixed in
3.3.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
2.18.0
minor
Dependencies (23)
+ 15 more
Changelog
Compare changes
|
|
2.17.1
patch
1 CVE
CVE-2020-15237
GHSA-5jjv-x4fq-qjwp
Oct 05, 2020
Possible timing attack in derivation_endpoint
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
ImpactWhen using the PatchesThe problem has been fixed by comparing sent and calculated signature in constant time, using WorkaroundsUsers of older Shrine versions can apply the following monkey-patch after loading the
ReferencesYou can read more about timing attacks here. Affected versions
0.9.0
1.0.0
1.1.0
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.1.0
2.1.1
+ 39 more Show less
2.10.0
2.10.1
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.17.1
2.18.0
2.18.1
2.19.0
2.19.1
2.19.2
2.19.3
2.19.4
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.9.0
3.0.0
3.0.0.alpha
3.0.0.beta
3.0.0.beta2
3.0.0.beta3
3.0.0.rc
3.0.1
3.1.0
3.2.0
3.2.1
3.2.2
Fixed in
3.3.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
2.17.1
patch
Dependencies (23)
+ 15 more
Changelog
Compare changes
|
|
2.17.0
minor
1 CVE
CVE-2020-15237
GHSA-5jjv-x4fq-qjwp
Oct 05, 2020
Possible timing attack in derivation_endpoint
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
ImpactWhen using the PatchesThe problem has been fixed by comparing sent and calculated signature in constant time, using WorkaroundsUsers of older Shrine versions can apply the following monkey-patch after loading the
ReferencesYou can read more about timing attacks here. Affected versions
0.9.0
1.0.0
1.1.0
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.1.0
2.1.1
+ 39 more Show less
2.10.0
2.10.1
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.17.1
2.18.0
2.18.1
2.19.0
2.19.1
2.19.2
2.19.3
2.19.4
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.9.0
3.0.0
3.0.0.alpha
3.0.0.beta
3.0.0.beta2
3.0.0.beta3
3.0.0.rc
3.0.1
3.1.0
3.2.0
3.2.1
3.2.2
Fixed in
3.3.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
2.17.0
minor
Dependencies (23)
+ 15 more
Changelog
Compare changes
|
|
2.16.0
minor
1 CVE
CVE-2020-15237
GHSA-5jjv-x4fq-qjwp
Oct 05, 2020
Possible timing attack in derivation_endpoint
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
ImpactWhen using the PatchesThe problem has been fixed by comparing sent and calculated signature in constant time, using WorkaroundsUsers of older Shrine versions can apply the following monkey-patch after loading the
ReferencesYou can read more about timing attacks here. Affected versions
0.9.0
1.0.0
1.1.0
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.1.0
2.1.1
+ 39 more Show less
2.10.0
2.10.1
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.17.1
2.18.0
2.18.1
2.19.0
2.19.1
2.19.2
2.19.3
2.19.4
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.9.0
3.0.0
3.0.0.alpha
3.0.0.beta
3.0.0.beta2
3.0.0.beta3
3.0.0.rc
3.0.1
3.1.0
3.2.0
3.2.1
3.2.2
Fixed in
3.3.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
2.16.0
minor
Dependencies (24)
+ 16 more
Changelog
Compare changes
|
|
2.15.0
minor
1 CVE
CVE-2020-15237
GHSA-5jjv-x4fq-qjwp
Oct 05, 2020
Possible timing attack in derivation_endpoint
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
ImpactWhen using the PatchesThe problem has been fixed by comparing sent and calculated signature in constant time, using WorkaroundsUsers of older Shrine versions can apply the following monkey-patch after loading the
ReferencesYou can read more about timing attacks here. Affected versions
0.9.0
1.0.0
1.1.0
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.1.0
2.1.1
+ 39 more Show less
2.10.0
2.10.1
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.17.1
2.18.0
2.18.1
2.19.0
2.19.1
2.19.2
2.19.3
2.19.4
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.9.0
3.0.0
3.0.0.alpha
3.0.0.beta
3.0.0.beta2
3.0.0.beta3
3.0.0.rc
3.0.1
3.1.0
3.2.0
3.2.1
3.2.2
Fixed in
3.3.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
2.15.0
minor
Dependencies (24)
+ 16 more
Changelog
Compare changes
|
|
2.14.0
minor
1 CVE
CVE-2020-15237
GHSA-5jjv-x4fq-qjwp
Oct 05, 2020
Possible timing attack in derivation_endpoint
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
ImpactWhen using the PatchesThe problem has been fixed by comparing sent and calculated signature in constant time, using WorkaroundsUsers of older Shrine versions can apply the following monkey-patch after loading the
ReferencesYou can read more about timing attacks here. Affected versions
0.9.0
1.0.0
1.1.0
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.1.0
2.1.1
+ 39 more Show less
2.10.0
2.10.1
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.17.1
2.18.0
2.18.1
2.19.0
2.19.1
2.19.2
2.19.3
2.19.4
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.9.0
3.0.0
3.0.0.alpha
3.0.0.beta
3.0.0.beta2
3.0.0.beta3
3.0.0.rc
3.0.1
3.1.0
3.2.0
3.2.1
3.2.2
Fixed in
3.3.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
2.14.0
minor
Dependencies (24)
+ 16 more
Changelog
Compare changes
|
|
2.13.0
minor
1 CVE
CVE-2020-15237
GHSA-5jjv-x4fq-qjwp
Oct 05, 2020
Possible timing attack in derivation_endpoint
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
ImpactWhen using the PatchesThe problem has been fixed by comparing sent and calculated signature in constant time, using WorkaroundsUsers of older Shrine versions can apply the following monkey-patch after loading the
ReferencesYou can read more about timing attacks here. Affected versions
0.9.0
1.0.0
1.1.0
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.1.0
2.1.1
+ 39 more Show less
2.10.0
2.10.1
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.17.1
2.18.0
2.18.1
2.19.0
2.19.1
2.19.2
2.19.3
2.19.4
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.9.0
3.0.0
3.0.0.alpha
3.0.0.beta
3.0.0.beta2
3.0.0.beta3
3.0.0.rc
3.0.1
3.1.0
3.2.0
3.2.1
3.2.2
Fixed in
3.3.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
2.13.0
minor
Dependencies (23)
+ 15 more
Changelog
Compare changes
|
|
2.12.0
minor
1 CVE
CVE-2020-15237
GHSA-5jjv-x4fq-qjwp
Oct 05, 2020
Possible timing attack in derivation_endpoint
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
ImpactWhen using the PatchesThe problem has been fixed by comparing sent and calculated signature in constant time, using WorkaroundsUsers of older Shrine versions can apply the following monkey-patch after loading the
ReferencesYou can read more about timing attacks here. Affected versions
0.9.0
1.0.0
1.1.0
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.1.0
2.1.1
+ 39 more Show less
2.10.0
2.10.1
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.17.1
2.18.0
2.18.1
2.19.0
2.19.1
2.19.2
2.19.3
2.19.4
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.9.0
3.0.0
3.0.0.alpha
3.0.0.beta
3.0.0.beta2
3.0.0.beta3
3.0.0.rc
3.0.1
3.1.0
3.2.0
3.2.1
3.2.2
Fixed in
3.3.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
2.12.0
minor
Dependencies (22)
+ 14 more
Changelog
Compare changes
|
|
2.11.0
minor
1 CVE
CVE-2020-15237
GHSA-5jjv-x4fq-qjwp
Oct 05, 2020
Possible timing attack in derivation_endpoint
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
ImpactWhen using the PatchesThe problem has been fixed by comparing sent and calculated signature in constant time, using WorkaroundsUsers of older Shrine versions can apply the following monkey-patch after loading the
ReferencesYou can read more about timing attacks here. Affected versions
0.9.0
1.0.0
1.1.0
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.1.0
2.1.1
+ 39 more Show less
2.10.0
2.10.1
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.17.1
2.18.0
2.18.1
2.19.0
2.19.1
2.19.2
2.19.3
2.19.4
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.9.0
3.0.0
3.0.0.alpha
3.0.0.beta
3.0.0.beta2
3.0.0.beta3
3.0.0.rc
3.0.1
3.1.0
3.2.0
3.2.1
3.2.2
Fixed in
3.3.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
2.11.0
minor
Dependencies (21)
+ 13 more
Changelog
Compare changes
|
|
2.10.1
patch
1 CVE
CVE-2020-15237
GHSA-5jjv-x4fq-qjwp
Oct 05, 2020
Possible timing attack in derivation_endpoint
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
ImpactWhen using the PatchesThe problem has been fixed by comparing sent and calculated signature in constant time, using WorkaroundsUsers of older Shrine versions can apply the following monkey-patch after loading the
ReferencesYou can read more about timing attacks here. Affected versions
0.9.0
1.0.0
1.1.0
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.1.0
2.1.1
+ 39 more Show less
2.10.0
2.10.1
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.17.1
2.18.0
2.18.1
2.19.0
2.19.1
2.19.2
2.19.3
2.19.4
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.9.0
3.0.0
3.0.0.alpha
3.0.0.beta
3.0.0.beta2
3.0.0.beta3
3.0.0.rc
3.0.1
3.1.0
3.2.0
3.2.1
3.2.2
Fixed in
3.3.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
2.10.1
patch
Dependencies (21)
+ 13 more
Changelog
Compare changes
|
|
2.10.0
minor
1 CVE
CVE-2020-15237
GHSA-5jjv-x4fq-qjwp
Oct 05, 2020
Possible timing attack in derivation_endpoint
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
ImpactWhen using the PatchesThe problem has been fixed by comparing sent and calculated signature in constant time, using WorkaroundsUsers of older Shrine versions can apply the following monkey-patch after loading the
ReferencesYou can read more about timing attacks here. Affected versions
0.9.0
1.0.0
1.1.0
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.1.0
2.1.1
+ 39 more Show less
2.10.0
2.10.1
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.17.1
2.18.0
2.18.1
2.19.0
2.19.1
2.19.2
2.19.3
2.19.4
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.9.0
3.0.0
3.0.0.alpha
3.0.0.beta
3.0.0.beta2
3.0.0.beta3
3.0.0.rc
3.0.1
3.1.0
3.2.0
3.2.1
3.2.2
Fixed in
3.3.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
2.10.0
minor
Dependencies (21)
+ 13 more
Changelog
Compare changes
|
|
2.9.0
minor
1 CVE
CVE-2020-15237
GHSA-5jjv-x4fq-qjwp
Oct 05, 2020
Possible timing attack in derivation_endpoint
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
ImpactWhen using the PatchesThe problem has been fixed by comparing sent and calculated signature in constant time, using WorkaroundsUsers of older Shrine versions can apply the following monkey-patch after loading the
ReferencesYou can read more about timing attacks here. Affected versions
0.9.0
1.0.0
1.1.0
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.1.0
2.1.1
+ 39 more Show less
2.10.0
2.10.1
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.17.1
2.18.0
2.18.1
2.19.0
2.19.1
2.19.2
2.19.3
2.19.4
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.9.0
3.0.0
3.0.0.alpha
3.0.0.beta
3.0.0.beta2
3.0.0.beta3
3.0.0.rc
3.0.1
3.1.0
3.2.0
3.2.1
3.2.2
Fixed in
3.3.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
2.9.0
minor
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
2.8.0
minor
1 CVE
CVE-2020-15237
GHSA-5jjv-x4fq-qjwp
Oct 05, 2020
Possible timing attack in derivation_endpoint
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
ImpactWhen using the PatchesThe problem has been fixed by comparing sent and calculated signature in constant time, using WorkaroundsUsers of older Shrine versions can apply the following monkey-patch after loading the
ReferencesYou can read more about timing attacks here. Affected versions
0.9.0
1.0.0
1.1.0
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.1.0
2.1.1
+ 39 more Show less
2.10.0
2.10.1
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.17.1
2.18.0
2.18.1
2.19.0
2.19.1
2.19.2
2.19.3
2.19.4
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.9.0
3.0.0
3.0.0.alpha
3.0.0.beta
3.0.0.beta2
3.0.0.beta3
3.0.0.rc
3.0.1
3.1.0
3.2.0
3.2.1
3.2.2
Fixed in
3.3.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
2.8.0
minor
Dependencies (18)
+ 10 more
Changelog
Compare changes
|
|
2.7.0
minor
1 CVE
CVE-2020-15237
GHSA-5jjv-x4fq-qjwp
Oct 05, 2020
Possible timing attack in derivation_endpoint
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
ImpactWhen using the PatchesThe problem has been fixed by comparing sent and calculated signature in constant time, using WorkaroundsUsers of older Shrine versions can apply the following monkey-patch after loading the
ReferencesYou can read more about timing attacks here. Affected versions
0.9.0
1.0.0
1.1.0
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.1.0
2.1.1
+ 39 more Show less
2.10.0
2.10.1
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.17.1
2.18.0
2.18.1
2.19.0
2.19.1
2.19.2
2.19.3
2.19.4
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.9.0
3.0.0
3.0.0.alpha
3.0.0.beta
3.0.0.beta2
3.0.0.beta3
3.0.0.rc
3.0.1
3.1.0
3.2.0
3.2.1
3.2.2
Fixed in
3.3.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
2.7.0
minor
Dependencies (18)
+ 10 more
Changelog
Compare changes
|
|
2.6.1
patch
1 CVE
CVE-2020-15237
GHSA-5jjv-x4fq-qjwp
Oct 05, 2020
Possible timing attack in derivation_endpoint
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
ImpactWhen using the PatchesThe problem has been fixed by comparing sent and calculated signature in constant time, using WorkaroundsUsers of older Shrine versions can apply the following monkey-patch after loading the
ReferencesYou can read more about timing attacks here. Affected versions
0.9.0
1.0.0
1.1.0
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.1.0
2.1.1
+ 39 more Show less
2.10.0
2.10.1
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.17.1
2.18.0
2.18.1
2.19.0
2.19.1
2.19.2
2.19.3
2.19.4
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.9.0
3.0.0
3.0.0.alpha
3.0.0.beta
3.0.0.beta2
3.0.0.beta3
3.0.0.rc
3.0.1
3.1.0
3.2.0
3.2.1
3.2.2
Fixed in
3.3.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
2.6.1
patch
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
2.6.0
minor
1 CVE
CVE-2020-15237
GHSA-5jjv-x4fq-qjwp
Oct 05, 2020
Possible timing attack in derivation_endpoint
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
ImpactWhen using the PatchesThe problem has been fixed by comparing sent and calculated signature in constant time, using WorkaroundsUsers of older Shrine versions can apply the following monkey-patch after loading the
ReferencesYou can read more about timing attacks here. Affected versions
0.9.0
1.0.0
1.1.0
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.1.0
2.1.1
+ 39 more Show less
2.10.0
2.10.1
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.17.1
2.18.0
2.18.1
2.19.0
2.19.1
2.19.2
2.19.3
2.19.4
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.9.0
3.0.0
3.0.0.alpha
3.0.0.beta
3.0.0.beta2
3.0.0.beta3
3.0.0.rc
3.0.1
3.1.0
3.2.0
3.2.1
3.2.2
Fixed in
3.3.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
2.6.0
minor
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
2.5.0
minor
1 CVE
CVE-2020-15237
GHSA-5jjv-x4fq-qjwp
Oct 05, 2020
Possible timing attack in derivation_endpoint
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
ImpactWhen using the PatchesThe problem has been fixed by comparing sent and calculated signature in constant time, using WorkaroundsUsers of older Shrine versions can apply the following monkey-patch after loading the
ReferencesYou can read more about timing attacks here. Affected versions
0.9.0
1.0.0
1.1.0
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.1.0
2.1.1
+ 39 more Show less
2.10.0
2.10.1
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.17.1
2.18.0
2.18.1
2.19.0
2.19.1
2.19.2
2.19.3
2.19.4
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.9.0
3.0.0
3.0.0.alpha
3.0.0.beta
3.0.0.beta2
3.0.0.beta3
3.0.0.rc
3.0.1
3.1.0
3.2.0
3.2.1
3.2.2
Fixed in
3.3.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
2.5.0
minor
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
2.4.1
patch
1 CVE
CVE-2020-15237
GHSA-5jjv-x4fq-qjwp
Oct 05, 2020
Possible timing attack in derivation_endpoint
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
ImpactWhen using the PatchesThe problem has been fixed by comparing sent and calculated signature in constant time, using WorkaroundsUsers of older Shrine versions can apply the following monkey-patch after loading the
ReferencesYou can read more about timing attacks here. Affected versions
0.9.0
1.0.0
1.1.0
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.1.0
2.1.1
+ 39 more Show less
2.10.0
2.10.1
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.17.1
2.18.0
2.18.1
2.19.0
2.19.1
2.19.2
2.19.3
2.19.4
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.9.0
3.0.0
3.0.0.alpha
3.0.0.beta
3.0.0.beta2
3.0.0.beta3
3.0.0.rc
3.0.1
3.1.0
3.2.0
3.2.1
3.2.2
Fixed in
3.3.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
2.4.1
patch
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
2.4.0
minor
1 CVE
CVE-2020-15237
GHSA-5jjv-x4fq-qjwp
Oct 05, 2020
Possible timing attack in derivation_endpoint
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
ImpactWhen using the PatchesThe problem has been fixed by comparing sent and calculated signature in constant time, using WorkaroundsUsers of older Shrine versions can apply the following monkey-patch after loading the
ReferencesYou can read more about timing attacks here. Affected versions
0.9.0
1.0.0
1.1.0
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.1.0
2.1.1
+ 39 more Show less
2.10.0
2.10.1
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.17.1
2.18.0
2.18.1
2.19.0
2.19.1
2.19.2
2.19.3
2.19.4
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.9.0
3.0.0
3.0.0.alpha
3.0.0.beta
3.0.0.beta2
3.0.0.beta3
3.0.0.rc
3.0.1
3.1.0
3.2.0
3.2.1
3.2.2
Fixed in
3.3.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
2.4.0
minor
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
2.3.1
patch
1 CVE
CVE-2020-15237
GHSA-5jjv-x4fq-qjwp
Oct 05, 2020
Possible timing attack in derivation_endpoint
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
ImpactWhen using the PatchesThe problem has been fixed by comparing sent and calculated signature in constant time, using WorkaroundsUsers of older Shrine versions can apply the following monkey-patch after loading the
ReferencesYou can read more about timing attacks here. Affected versions
0.9.0
1.0.0
1.1.0
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.1.0
2.1.1
+ 39 more Show less
2.10.0
2.10.1
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.17.1
2.18.0
2.18.1
2.19.0
2.19.1
2.19.2
2.19.3
2.19.4
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.9.0
3.0.0
3.0.0.alpha
3.0.0.beta
3.0.0.beta2
3.0.0.beta3
3.0.0.rc
3.0.1
3.1.0
3.2.0
3.2.1
3.2.2
Fixed in
3.3.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
2.3.1
patch
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
2.3.0
minor
1 CVE
CVE-2020-15237
GHSA-5jjv-x4fq-qjwp
Oct 05, 2020
Possible timing attack in derivation_endpoint
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
ImpactWhen using the PatchesThe problem has been fixed by comparing sent and calculated signature in constant time, using WorkaroundsUsers of older Shrine versions can apply the following monkey-patch after loading the
ReferencesYou can read more about timing attacks here. Affected versions
0.9.0
1.0.0
1.1.0
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.1.0
2.1.1
+ 39 more Show less
2.10.0
2.10.1
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.17.1
2.18.0
2.18.1
2.19.0
2.19.1
2.19.2
2.19.3
2.19.4
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.9.0
3.0.0
3.0.0.alpha
3.0.0.beta
3.0.0.beta2
3.0.0.beta3
3.0.0.rc
3.0.1
3.1.0
3.2.0
3.2.1
3.2.2
Fixed in
3.3.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
2.3.0
minor
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
2.2.0
minor
1 CVE
CVE-2020-15237
GHSA-5jjv-x4fq-qjwp
Oct 05, 2020
Possible timing attack in derivation_endpoint
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
ImpactWhen using the PatchesThe problem has been fixed by comparing sent and calculated signature in constant time, using WorkaroundsUsers of older Shrine versions can apply the following monkey-patch after loading the
ReferencesYou can read more about timing attacks here. Affected versions
0.9.0
1.0.0
1.1.0
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.1.0
2.1.1
+ 39 more Show less
2.10.0
2.10.1
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.17.1
2.18.0
2.18.1
2.19.0
2.19.1
2.19.2
2.19.3
2.19.4
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.9.0
3.0.0
3.0.0.alpha
3.0.0.beta
3.0.0.beta2
3.0.0.beta3
3.0.0.rc
3.0.1
3.1.0
3.2.0
3.2.1
3.2.2
Fixed in
3.3.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
2.2.0
minor
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
2.1.1
patch
1 CVE
CVE-2020-15237
GHSA-5jjv-x4fq-qjwp
Oct 05, 2020
Possible timing attack in derivation_endpoint
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
ImpactWhen using the PatchesThe problem has been fixed by comparing sent and calculated signature in constant time, using WorkaroundsUsers of older Shrine versions can apply the following monkey-patch after loading the
ReferencesYou can read more about timing attacks here. Affected versions
0.9.0
1.0.0
1.1.0
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.1.0
2.1.1
+ 39 more Show less
2.10.0
2.10.1
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.17.1
2.18.0
2.18.1
2.19.0
2.19.1
2.19.2
2.19.3
2.19.4
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.9.0
3.0.0
3.0.0.alpha
3.0.0.beta
3.0.0.beta2
3.0.0.beta3
3.0.0.rc
3.0.1
3.1.0
3.2.0
3.2.1
3.2.2
Fixed in
3.3.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
2.1.1
patch
Dependencies (18)
+ 10 more
Changelog
Compare changes
|
|
2.1.0
minor
1 CVE
CVE-2020-15237
GHSA-5jjv-x4fq-qjwp
Oct 05, 2020
Possible timing attack in derivation_endpoint
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
ImpactWhen using the PatchesThe problem has been fixed by comparing sent and calculated signature in constant time, using WorkaroundsUsers of older Shrine versions can apply the following monkey-patch after loading the
ReferencesYou can read more about timing attacks here. Affected versions
0.9.0
1.0.0
1.1.0
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.1.0
2.1.1
+ 39 more Show less
2.10.0
2.10.1
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.17.1
2.18.0
2.18.1
2.19.0
2.19.1
2.19.2
2.19.3
2.19.4
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.9.0
3.0.0
3.0.0.alpha
3.0.0.beta
3.0.0.beta2
3.0.0.beta3
3.0.0.rc
3.0.1
3.1.0
3.2.0
3.2.1
3.2.2
Fixed in
3.3.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
2.1.0
minor
Dependencies (18)
+ 10 more
Changelog
Compare changes
|
|
2.0.1
patch
1 CVE
CVE-2020-15237
GHSA-5jjv-x4fq-qjwp
Oct 05, 2020
Possible timing attack in derivation_endpoint
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
ImpactWhen using the PatchesThe problem has been fixed by comparing sent and calculated signature in constant time, using WorkaroundsUsers of older Shrine versions can apply the following monkey-patch after loading the
ReferencesYou can read more about timing attacks here. Affected versions
0.9.0
1.0.0
1.1.0
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.1.0
2.1.1
+ 39 more Show less
2.10.0
2.10.1
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.17.1
2.18.0
2.18.1
2.19.0
2.19.1
2.19.2
2.19.3
2.19.4
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.9.0
3.0.0
3.0.0.alpha
3.0.0.beta
3.0.0.beta2
3.0.0.beta3
3.0.0.rc
3.0.1
3.1.0
3.2.0
3.2.1
3.2.2
Fixed in
3.3.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
2.0.1
patch
Dependencies (18)
+ 10 more
Changelog
Compare changes
|