sinatra
Sinatra is a DSL for quickly creating web applications in Ruby with minimal effort.
Activity
- Latest release
- 11mo ago
- Total releases
- 108
- Cadence
- ~41 days
- Last 12 months
- 2
Reach
- Stars
- —
Details
- License
- MIT
- First release
- Oct 04, 2007
| Version | Released | |
|---|---|---|
4.2.1
patch
| ||
4.2.0
minor
| ||
4.0.1
patch
2 CVEs
CVE-2025-61921
GHSA-mr3q-g2mv-mr4q
Oct 10, 2025
Sinatra is vulnerable to ReDoS through ETag header value generation
Low
Network
Low
None
None
SummaryThere is a denial of service vulnerability in the DetailsCarefully crafted input can cause Resources
Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 94 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.1.0
4.1.1
Fixed in
4.2.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-21510
GHSA-hxx2-7vcw-mqr3
Nov 01, 2024
Sinatra vulnerable to Reliance on Untrusted Inputs in a Security Decision
Medium
Network
Low
None
Versions of the package sinatra from 0.0.0 are vulnerable to Reliance on Untrusted Inputs in a Security Decision via the X-Forwarded-Host (XFH) header. When making a request to a method with redirect applied, it is possible to trigger an Open Redirect Attack by inserting an arbitrary address into this header. If used for caching purposes, such as with servers like Nginx, or as a reverse proxy, without handling the X-Forwarded-Host header, attackers can potentially exploit Cache Poisoning or Routing-based SSRF. Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 92 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
Fixed in
4.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
4.1.1
patch
1 CVE
CVE-2025-61921
GHSA-mr3q-g2mv-mr4q
Oct 10, 2025
Sinatra is vulnerable to ReDoS through ETag header value generation
Low
Network
Low
None
None
SummaryThere is a denial of service vulnerability in the DetailsCarefully crafted input can cause Resources
Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 94 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.1.0
4.1.1
Fixed in
4.2.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
4.1.0
minor
1 CVE
CVE-2025-61921
GHSA-mr3q-g2mv-mr4q
Oct 10, 2025
Sinatra is vulnerable to ReDoS through ETag header value generation
Low
Network
Low
None
None
SummaryThere is a denial of service vulnerability in the DetailsCarefully crafted input can cause Resources
Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 94 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.1.0
4.1.1
Fixed in
4.2.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
4.0.0
major
2 CVEs
CVE-2025-61921
GHSA-mr3q-g2mv-mr4q
Oct 10, 2025
Sinatra is vulnerable to ReDoS through ETag header value generation
Low
Network
Low
None
None
SummaryThere is a denial of service vulnerability in the DetailsCarefully crafted input can cause Resources
Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 94 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.1.0
4.1.1
Fixed in
4.2.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-21510
GHSA-hxx2-7vcw-mqr3
Nov 01, 2024
Sinatra vulnerable to Reliance on Untrusted Inputs in a Security Decision
Medium
Network
Low
None
Versions of the package sinatra from 0.0.0 are vulnerable to Reliance on Untrusted Inputs in a Security Decision via the X-Forwarded-Host (XFH) header. When making a request to a method with redirect applied, it is possible to trigger an Open Redirect Attack by inserting an arbitrary address into this header. If used for caching purposes, such as with servers like Nginx, or as a reverse proxy, without handling the X-Forwarded-Host header, attackers can potentially exploit Cache Poisoning or Routing-based SSRF. Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 92 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
Fixed in
4.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.2.0
minor
2 CVEs
CVE-2025-61921
GHSA-mr3q-g2mv-mr4q
Oct 10, 2025
Sinatra is vulnerable to ReDoS through ETag header value generation
Low
Network
Low
None
None
SummaryThere is a denial of service vulnerability in the DetailsCarefully crafted input can cause Resources
Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 94 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.1.0
4.1.1
Fixed in
4.2.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-21510
GHSA-hxx2-7vcw-mqr3
Nov 01, 2024
Sinatra vulnerable to Reliance on Untrusted Inputs in a Security Decision
Medium
Network
Low
None
Versions of the package sinatra from 0.0.0 are vulnerable to Reliance on Untrusted Inputs in a Security Decision via the X-Forwarded-Host (XFH) header. When making a request to a method with redirect applied, it is possible to trigger an Open Redirect Attack by inserting an arbitrary address into this header. If used for caching purposes, such as with servers like Nginx, or as a reverse proxy, without handling the X-Forwarded-Host header, attackers can potentially exploit Cache Poisoning or Routing-based SSRF. Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 92 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
Fixed in
4.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.1.0
minor
2 CVEs
CVE-2025-61921
GHSA-mr3q-g2mv-mr4q
Oct 10, 2025
Sinatra is vulnerable to ReDoS through ETag header value generation
Low
Network
Low
None
None
SummaryThere is a denial of service vulnerability in the DetailsCarefully crafted input can cause Resources
Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 94 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.1.0
4.1.1
Fixed in
4.2.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-21510
GHSA-hxx2-7vcw-mqr3
Nov 01, 2024
Sinatra vulnerable to Reliance on Untrusted Inputs in a Security Decision
Medium
Network
Low
None
Versions of the package sinatra from 0.0.0 are vulnerable to Reliance on Untrusted Inputs in a Security Decision via the X-Forwarded-Host (XFH) header. When making a request to a method with redirect applied, it is possible to trigger an Open Redirect Attack by inserting an arbitrary address into this header. If used for caching purposes, such as with servers like Nginx, or as a reverse proxy, without handling the X-Forwarded-Host header, attackers can potentially exploit Cache Poisoning or Routing-based SSRF. Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 92 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
Fixed in
4.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.0.6
patch
2 CVEs
CVE-2025-61921
GHSA-mr3q-g2mv-mr4q
Oct 10, 2025
Sinatra is vulnerable to ReDoS through ETag header value generation
Low
Network
Low
None
None
SummaryThere is a denial of service vulnerability in the DetailsCarefully crafted input can cause Resources
Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 94 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.1.0
4.1.1
Fixed in
4.2.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-21510
GHSA-hxx2-7vcw-mqr3
Nov 01, 2024
Sinatra vulnerable to Reliance on Untrusted Inputs in a Security Decision
Medium
Network
Low
None
Versions of the package sinatra from 0.0.0 are vulnerable to Reliance on Untrusted Inputs in a Security Decision via the X-Forwarded-Host (XFH) header. When making a request to a method with redirect applied, it is possible to trigger an Open Redirect Attack by inserting an arbitrary address into this header. If used for caching purposes, such as with servers like Nginx, or as a reverse proxy, without handling the X-Forwarded-Host header, attackers can potentially exploit Cache Poisoning or Routing-based SSRF. Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 92 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
Fixed in
4.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.2.4
patch
2 CVEs
CVE-2025-61921
GHSA-mr3q-g2mv-mr4q
Oct 10, 2025
Sinatra is vulnerable to ReDoS through ETag header value generation
Low
Network
Low
None
None
SummaryThere is a denial of service vulnerability in the DetailsCarefully crafted input can cause Resources
Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 94 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.1.0
4.1.1
Fixed in
4.2.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-21510
GHSA-hxx2-7vcw-mqr3
Nov 01, 2024
Sinatra vulnerable to Reliance on Untrusted Inputs in a Security Decision
Medium
Network
Low
None
Versions of the package sinatra from 0.0.0 are vulnerable to Reliance on Untrusted Inputs in a Security Decision via the X-Forwarded-Host (XFH) header. When making a request to a method with redirect applied, it is possible to trigger an Open Redirect Attack by inserting an arbitrary address into this header. If used for caching purposes, such as with servers like Nginx, or as a reverse proxy, without handling the X-Forwarded-Host header, attackers can potentially exploit Cache Poisoning or Routing-based SSRF. Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 92 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
Fixed in
4.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.0.5
patch
2 CVEs
CVE-2025-61921
GHSA-mr3q-g2mv-mr4q
Oct 10, 2025
Sinatra is vulnerable to ReDoS through ETag header value generation
Low
Network
Low
None
None
SummaryThere is a denial of service vulnerability in the DetailsCarefully crafted input can cause Resources
Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 94 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.1.0
4.1.1
Fixed in
4.2.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-21510
GHSA-hxx2-7vcw-mqr3
Nov 01, 2024
Sinatra vulnerable to Reliance on Untrusted Inputs in a Security Decision
Medium
Network
Low
None
Versions of the package sinatra from 0.0.0 are vulnerable to Reliance on Untrusted Inputs in a Security Decision via the X-Forwarded-Host (XFH) header. When making a request to a method with redirect applied, it is possible to trigger an Open Redirect Attack by inserting an arbitrary address into this header. If used for caching purposes, such as with servers like Nginx, or as a reverse proxy, without handling the X-Forwarded-Host header, attackers can potentially exploit Cache Poisoning or Routing-based SSRF. Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 92 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
Fixed in
4.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.0.4
patch
2 CVEs
CVE-2025-61921
GHSA-mr3q-g2mv-mr4q
Oct 10, 2025
Sinatra is vulnerable to ReDoS through ETag header value generation
Low
Network
Low
None
None
SummaryThere is a denial of service vulnerability in the DetailsCarefully crafted input can cause Resources
Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 94 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.1.0
4.1.1
Fixed in
4.2.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-21510
GHSA-hxx2-7vcw-mqr3
Nov 01, 2024
Sinatra vulnerable to Reliance on Untrusted Inputs in a Security Decision
Medium
Network
Low
None
Versions of the package sinatra from 0.0.0 are vulnerable to Reliance on Untrusted Inputs in a Security Decision via the X-Forwarded-Host (XFH) header. When making a request to a method with redirect applied, it is possible to trigger an Open Redirect Attack by inserting an arbitrary address into this header. If used for caching purposes, such as with servers like Nginx, or as a reverse proxy, without handling the X-Forwarded-Host header, attackers can potentially exploit Cache Poisoning or Routing-based SSRF. Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 92 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
Fixed in
4.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.2.3
patch
2 CVEs
CVE-2025-61921
GHSA-mr3q-g2mv-mr4q
Oct 10, 2025
Sinatra is vulnerable to ReDoS through ETag header value generation
Low
Network
Low
None
None
SummaryThere is a denial of service vulnerability in the DetailsCarefully crafted input can cause Resources
Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 94 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.1.0
4.1.1
Fixed in
4.2.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-21510
GHSA-hxx2-7vcw-mqr3
Nov 01, 2024
Sinatra vulnerable to Reliance on Untrusted Inputs in a Security Decision
Medium
Network
Low
None
Versions of the package sinatra from 0.0.0 are vulnerable to Reliance on Untrusted Inputs in a Security Decision via the X-Forwarded-Host (XFH) header. When making a request to a method with redirect applied, it is possible to trigger an Open Redirect Attack by inserting an arbitrary address into this header. If used for caching purposes, such as with servers like Nginx, or as a reverse proxy, without handling the X-Forwarded-Host header, attackers can potentially exploit Cache Poisoning or Routing-based SSRF. Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 92 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
Fixed in
4.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.0.3
patch
3 CVEs
CVE-2025-61921
GHSA-mr3q-g2mv-mr4q
Oct 10, 2025
Sinatra is vulnerable to ReDoS through ETag header value generation
Low
Network
Low
None
None
SummaryThere is a denial of service vulnerability in the DetailsCarefully crafted input can cause Resources
Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 94 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.1.0
4.1.1
Fixed in
4.2.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-21510
GHSA-hxx2-7vcw-mqr3
Nov 01, 2024
Sinatra vulnerable to Reliance on Untrusted Inputs in a Security Decision
Medium
Network
Low
None
Versions of the package sinatra from 0.0.0 are vulnerable to Reliance on Untrusted Inputs in a Security Decision via the X-Forwarded-Host (XFH) header. When making a request to a method with redirect applied, it is possible to trigger an Open Redirect Attack by inserting an arbitrary address into this header. If used for caching purposes, such as with servers like Nginx, or as a reverse proxy, without handling the X-Forwarded-Host header, attackers can potentially exploit Cache Poisoning or Routing-based SSRF. Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 92 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
Fixed in
4.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-45442
GHSA-2x8x-jmrp-phxw
Nov 30, 2022
Sinatra vulnerable to Reflected File Download attack
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
DescriptionAn issue was discovered in Sinatra 2.0 before 2.2.3 and 3.0 before 3.0.4. An application is vulnerable to a reflected file download (RFD) attack that sets the Content-Disposition header of a response when the filename is derived from user-supplied input. References
Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
2.0.0
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
+ 7 more Show less
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
Fixed in
2.2.3
3.0.4
References
Updated Feb 04, 2026 · Source: OSV.dev | ||
3.0.2
patch
3 CVEs
CVE-2025-61921
GHSA-mr3q-g2mv-mr4q
Oct 10, 2025
Sinatra is vulnerable to ReDoS through ETag header value generation
Low
Network
Low
None
None
SummaryThere is a denial of service vulnerability in the DetailsCarefully crafted input can cause Resources
Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 94 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.1.0
4.1.1
Fixed in
4.2.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-21510
GHSA-hxx2-7vcw-mqr3
Nov 01, 2024
Sinatra vulnerable to Reliance on Untrusted Inputs in a Security Decision
Medium
Network
Low
None
Versions of the package sinatra from 0.0.0 are vulnerable to Reliance on Untrusted Inputs in a Security Decision via the X-Forwarded-Host (XFH) header. When making a request to a method with redirect applied, it is possible to trigger an Open Redirect Attack by inserting an arbitrary address into this header. If used for caching purposes, such as with servers like Nginx, or as a reverse proxy, without handling the X-Forwarded-Host header, attackers can potentially exploit Cache Poisoning or Routing-based SSRF. Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 92 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
Fixed in
4.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-45442
GHSA-2x8x-jmrp-phxw
Nov 30, 2022
Sinatra vulnerable to Reflected File Download attack
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
DescriptionAn issue was discovered in Sinatra 2.0 before 2.2.3 and 3.0 before 3.0.4. An application is vulnerable to a reflected file download (RFD) attack that sets the Content-Disposition header of a response when the filename is derived from user-supplied input. References
Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
2.0.0
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
+ 7 more Show less
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
Fixed in
2.2.3
3.0.4
References
Updated Feb 04, 2026 · Source: OSV.dev | ||
3.0.1
patch
3 CVEs
CVE-2025-61921
GHSA-mr3q-g2mv-mr4q
Oct 10, 2025
Sinatra is vulnerable to ReDoS through ETag header value generation
Low
Network
Low
None
None
SummaryThere is a denial of service vulnerability in the DetailsCarefully crafted input can cause Resources
Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 94 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.1.0
4.1.1
Fixed in
4.2.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-21510
GHSA-hxx2-7vcw-mqr3
Nov 01, 2024
Sinatra vulnerable to Reliance on Untrusted Inputs in a Security Decision
Medium
Network
Low
None
Versions of the package sinatra from 0.0.0 are vulnerable to Reliance on Untrusted Inputs in a Security Decision via the X-Forwarded-Host (XFH) header. When making a request to a method with redirect applied, it is possible to trigger an Open Redirect Attack by inserting an arbitrary address into this header. If used for caching purposes, such as with servers like Nginx, or as a reverse proxy, without handling the X-Forwarded-Host header, attackers can potentially exploit Cache Poisoning or Routing-based SSRF. Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 92 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
Fixed in
4.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-45442
GHSA-2x8x-jmrp-phxw
Nov 30, 2022
Sinatra vulnerable to Reflected File Download attack
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
DescriptionAn issue was discovered in Sinatra 2.0 before 2.2.3 and 3.0 before 3.0.4. An application is vulnerable to a reflected file download (RFD) attack that sets the Content-Disposition header of a response when the filename is derived from user-supplied input. References
Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
2.0.0
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
+ 7 more Show less
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
Fixed in
2.2.3
3.0.4
References
Updated Feb 04, 2026 · Source: OSV.dev | ||
3.0.0
major
3 CVEs
CVE-2025-61921
GHSA-mr3q-g2mv-mr4q
Oct 10, 2025
Sinatra is vulnerable to ReDoS through ETag header value generation
Low
Network
Low
None
None
SummaryThere is a denial of service vulnerability in the DetailsCarefully crafted input can cause Resources
Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 94 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.1.0
4.1.1
Fixed in
4.2.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-21510
GHSA-hxx2-7vcw-mqr3
Nov 01, 2024
Sinatra vulnerable to Reliance on Untrusted Inputs in a Security Decision
Medium
Network
Low
None
Versions of the package sinatra from 0.0.0 are vulnerable to Reliance on Untrusted Inputs in a Security Decision via the X-Forwarded-Host (XFH) header. When making a request to a method with redirect applied, it is possible to trigger an Open Redirect Attack by inserting an arbitrary address into this header. If used for caching purposes, such as with servers like Nginx, or as a reverse proxy, without handling the X-Forwarded-Host header, attackers can potentially exploit Cache Poisoning or Routing-based SSRF. Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 92 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
Fixed in
4.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-45442
GHSA-2x8x-jmrp-phxw
Nov 30, 2022
Sinatra vulnerable to Reflected File Download attack
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
DescriptionAn issue was discovered in Sinatra 2.0 before 2.2.3 and 3.0 before 3.0.4. An application is vulnerable to a reflected file download (RFD) attack that sets the Content-Disposition header of a response when the filename is derived from user-supplied input. References
Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
2.0.0
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
+ 7 more Show less
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
Fixed in
2.2.3
3.0.4
References
Updated Feb 04, 2026 · Source: OSV.dev | ||
2.2.2
patch
3 CVEs
CVE-2025-61921
GHSA-mr3q-g2mv-mr4q
Oct 10, 2025
Sinatra is vulnerable to ReDoS through ETag header value generation
Low
Network
Low
None
None
SummaryThere is a denial of service vulnerability in the DetailsCarefully crafted input can cause Resources
Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 94 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.1.0
4.1.1
Fixed in
4.2.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-21510
GHSA-hxx2-7vcw-mqr3
Nov 01, 2024
Sinatra vulnerable to Reliance on Untrusted Inputs in a Security Decision
Medium
Network
Low
None
Versions of the package sinatra from 0.0.0 are vulnerable to Reliance on Untrusted Inputs in a Security Decision via the X-Forwarded-Host (XFH) header. When making a request to a method with redirect applied, it is possible to trigger an Open Redirect Attack by inserting an arbitrary address into this header. If used for caching purposes, such as with servers like Nginx, or as a reverse proxy, without handling the X-Forwarded-Host header, attackers can potentially exploit Cache Poisoning or Routing-based SSRF. Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 92 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
Fixed in
4.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-45442
GHSA-2x8x-jmrp-phxw
Nov 30, 2022
Sinatra vulnerable to Reflected File Download attack
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
DescriptionAn issue was discovered in Sinatra 2.0 before 2.2.3 and 3.0 before 3.0.4. An application is vulnerable to a reflected file download (RFD) attack that sets the Content-Disposition header of a response when the filename is derived from user-supplied input. References
Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
2.0.0
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
+ 7 more Show less
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
Fixed in
2.2.3
3.0.4
References
Updated Feb 04, 2026 · Source: OSV.dev | ||
2.2.1
patch
3 CVEs
CVE-2025-61921
GHSA-mr3q-g2mv-mr4q
Oct 10, 2025
Sinatra is vulnerable to ReDoS through ETag header value generation
Low
Network
Low
None
None
SummaryThere is a denial of service vulnerability in the DetailsCarefully crafted input can cause Resources
Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 94 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.1.0
4.1.1
Fixed in
4.2.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-21510
GHSA-hxx2-7vcw-mqr3
Nov 01, 2024
Sinatra vulnerable to Reliance on Untrusted Inputs in a Security Decision
Medium
Network
Low
None
Versions of the package sinatra from 0.0.0 are vulnerable to Reliance on Untrusted Inputs in a Security Decision via the X-Forwarded-Host (XFH) header. When making a request to a method with redirect applied, it is possible to trigger an Open Redirect Attack by inserting an arbitrary address into this header. If used for caching purposes, such as with servers like Nginx, or as a reverse proxy, without handling the X-Forwarded-Host header, attackers can potentially exploit Cache Poisoning or Routing-based SSRF. Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 92 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
Fixed in
4.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-45442
GHSA-2x8x-jmrp-phxw
Nov 30, 2022
Sinatra vulnerable to Reflected File Download attack
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
DescriptionAn issue was discovered in Sinatra 2.0 before 2.2.3 and 3.0 before 3.0.4. An application is vulnerable to a reflected file download (RFD) attack that sets the Content-Disposition header of a response when the filename is derived from user-supplied input. References
Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
2.0.0
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
+ 7 more Show less
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
Fixed in
2.2.3
3.0.4
References
Updated Feb 04, 2026 · Source: OSV.dev | ||
2.2.0
minor
3 CVEs
CVE-2025-61921
GHSA-mr3q-g2mv-mr4q
Oct 10, 2025
Sinatra is vulnerable to ReDoS through ETag header value generation
Low
Network
Low
None
None
SummaryThere is a denial of service vulnerability in the DetailsCarefully crafted input can cause Resources
Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 94 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.1.0
4.1.1
Fixed in
4.2.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-21510
GHSA-hxx2-7vcw-mqr3
Nov 01, 2024
Sinatra vulnerable to Reliance on Untrusted Inputs in a Security Decision
Medium
Network
Low
None
Versions of the package sinatra from 0.0.0 are vulnerable to Reliance on Untrusted Inputs in a Security Decision via the X-Forwarded-Host (XFH) header. When making a request to a method with redirect applied, it is possible to trigger an Open Redirect Attack by inserting an arbitrary address into this header. If used for caching purposes, such as with servers like Nginx, or as a reverse proxy, without handling the X-Forwarded-Host header, attackers can potentially exploit Cache Poisoning or Routing-based SSRF. Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 92 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
Fixed in
4.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-45442
GHSA-2x8x-jmrp-phxw
Nov 30, 2022
Sinatra vulnerable to Reflected File Download attack
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
DescriptionAn issue was discovered in Sinatra 2.0 before 2.2.3 and 3.0 before 3.0.4. An application is vulnerable to a reflected file download (RFD) attack that sets the Content-Disposition header of a response when the filename is derived from user-supplied input. References
Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
2.0.0
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
+ 7 more Show less
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
Fixed in
2.2.3
3.0.4
References
Updated Feb 04, 2026 · Source: OSV.dev | ||
2.1.0
minor
4 CVEs
CVE-2025-61921
GHSA-mr3q-g2mv-mr4q
Oct 10, 2025
Sinatra is vulnerable to ReDoS through ETag header value generation
Low
Network
Low
None
None
SummaryThere is a denial of service vulnerability in the DetailsCarefully crafted input can cause Resources
Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 94 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.1.0
4.1.1
Fixed in
4.2.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-21510
GHSA-hxx2-7vcw-mqr3
Nov 01, 2024
Sinatra vulnerable to Reliance on Untrusted Inputs in a Security Decision
Medium
Network
Low
None
Versions of the package sinatra from 0.0.0 are vulnerable to Reliance on Untrusted Inputs in a Security Decision via the X-Forwarded-Host (XFH) header. When making a request to a method with redirect applied, it is possible to trigger an Open Redirect Attack by inserting an arbitrary address into this header. If used for caching purposes, such as with servers like Nginx, or as a reverse proxy, without handling the X-Forwarded-Host header, attackers can potentially exploit Cache Poisoning or Routing-based SSRF. Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 92 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
Fixed in
4.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-45442
GHSA-2x8x-jmrp-phxw
Nov 30, 2022
Sinatra vulnerable to Reflected File Download attack
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
DescriptionAn issue was discovered in Sinatra 2.0 before 2.2.3 and 3.0 before 3.0.4. An application is vulnerable to a reflected file download (RFD) attack that sets the Content-Disposition header of a response when the filename is derived from user-supplied input. References
Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
2.0.0
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
+ 7 more Show less
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
Fixed in
2.2.3
3.0.4
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-29970
GHSA-qp49-3pvw-x4m5
May 03, 2022
sinatra does not validate expanded path matches
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Sinatra before 2.2.0 does not validate that the expanded path matches public_dir when serving static files. Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 76 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
Fixed in
2.2.0
References
Updated Nov 04, 2025 · Source: OSV.dev | ||
2.0.8
patch
4 CVEs
CVE-2025-61921
GHSA-mr3q-g2mv-mr4q
Oct 10, 2025
Sinatra is vulnerable to ReDoS through ETag header value generation
Low
Network
Low
None
None
SummaryThere is a denial of service vulnerability in the DetailsCarefully crafted input can cause Resources
Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 94 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.1.0
4.1.1
Fixed in
4.2.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-21510
GHSA-hxx2-7vcw-mqr3
Nov 01, 2024
Sinatra vulnerable to Reliance on Untrusted Inputs in a Security Decision
Medium
Network
Low
None
Versions of the package sinatra from 0.0.0 are vulnerable to Reliance on Untrusted Inputs in a Security Decision via the X-Forwarded-Host (XFH) header. When making a request to a method with redirect applied, it is possible to trigger an Open Redirect Attack by inserting an arbitrary address into this header. If used for caching purposes, such as with servers like Nginx, or as a reverse proxy, without handling the X-Forwarded-Host header, attackers can potentially exploit Cache Poisoning or Routing-based SSRF. Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 92 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
Fixed in
4.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-45442
GHSA-2x8x-jmrp-phxw
Nov 30, 2022
Sinatra vulnerable to Reflected File Download attack
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
DescriptionAn issue was discovered in Sinatra 2.0 before 2.2.3 and 3.0 before 3.0.4. An application is vulnerable to a reflected file download (RFD) attack that sets the Content-Disposition header of a response when the filename is derived from user-supplied input. References
Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
2.0.0
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
+ 7 more Show less
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
Fixed in
2.2.3
3.0.4
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-29970
GHSA-qp49-3pvw-x4m5
May 03, 2022
sinatra does not validate expanded path matches
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Sinatra before 2.2.0 does not validate that the expanded path matches public_dir when serving static files. Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 76 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
Fixed in
2.2.0
References
Updated Nov 04, 2025 · Source: OSV.dev | ||
2.0.8.1
patch
4 CVEs
CVE-2025-61921
GHSA-mr3q-g2mv-mr4q
Oct 10, 2025
Sinatra is vulnerable to ReDoS through ETag header value generation
Low
Network
Low
None
None
SummaryThere is a denial of service vulnerability in the DetailsCarefully crafted input can cause Resources
Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 94 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.1.0
4.1.1
Fixed in
4.2.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-21510
GHSA-hxx2-7vcw-mqr3
Nov 01, 2024
Sinatra vulnerable to Reliance on Untrusted Inputs in a Security Decision
Medium
Network
Low
None
Versions of the package sinatra from 0.0.0 are vulnerable to Reliance on Untrusted Inputs in a Security Decision via the X-Forwarded-Host (XFH) header. When making a request to a method with redirect applied, it is possible to trigger an Open Redirect Attack by inserting an arbitrary address into this header. If used for caching purposes, such as with servers like Nginx, or as a reverse proxy, without handling the X-Forwarded-Host header, attackers can potentially exploit Cache Poisoning or Routing-based SSRF. Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 92 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
Fixed in
4.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-45442
GHSA-2x8x-jmrp-phxw
Nov 30, 2022
Sinatra vulnerable to Reflected File Download attack
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
DescriptionAn issue was discovered in Sinatra 2.0 before 2.2.3 and 3.0 before 3.0.4. An application is vulnerable to a reflected file download (RFD) attack that sets the Content-Disposition header of a response when the filename is derived from user-supplied input. References
Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
2.0.0
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
+ 7 more Show less
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
Fixed in
2.2.3
3.0.4
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-29970
GHSA-qp49-3pvw-x4m5
May 03, 2022
sinatra does not validate expanded path matches
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Sinatra before 2.2.0 does not validate that the expanded path matches public_dir when serving static files. Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 76 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
Fixed in
2.2.0
References
Updated Nov 04, 2025 · Source: OSV.dev | ||
2.0.7
patch
4 CVEs
CVE-2025-61921
GHSA-mr3q-g2mv-mr4q
Oct 10, 2025
Sinatra is vulnerable to ReDoS through ETag header value generation
Low
Network
Low
None
None
SummaryThere is a denial of service vulnerability in the DetailsCarefully crafted input can cause Resources
Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 94 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.1.0
4.1.1
Fixed in
4.2.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-21510
GHSA-hxx2-7vcw-mqr3
Nov 01, 2024
Sinatra vulnerable to Reliance on Untrusted Inputs in a Security Decision
Medium
Network
Low
None
Versions of the package sinatra from 0.0.0 are vulnerable to Reliance on Untrusted Inputs in a Security Decision via the X-Forwarded-Host (XFH) header. When making a request to a method with redirect applied, it is possible to trigger an Open Redirect Attack by inserting an arbitrary address into this header. If used for caching purposes, such as with servers like Nginx, or as a reverse proxy, without handling the X-Forwarded-Host header, attackers can potentially exploit Cache Poisoning or Routing-based SSRF. Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 92 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
Fixed in
4.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-45442
GHSA-2x8x-jmrp-phxw
Nov 30, 2022
Sinatra vulnerable to Reflected File Download attack
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
DescriptionAn issue was discovered in Sinatra 2.0 before 2.2.3 and 3.0 before 3.0.4. An application is vulnerable to a reflected file download (RFD) attack that sets the Content-Disposition header of a response when the filename is derived from user-supplied input. References
Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
2.0.0
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
+ 7 more Show less
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
Fixed in
2.2.3
3.0.4
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-29970
GHSA-qp49-3pvw-x4m5
May 03, 2022
sinatra does not validate expanded path matches
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Sinatra before 2.2.0 does not validate that the expanded path matches public_dir when serving static files. Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 76 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
Fixed in
2.2.0
References
Updated Nov 04, 2025 · Source: OSV.dev | ||
2.0.6
patch
4 CVEs
CVE-2025-61921
GHSA-mr3q-g2mv-mr4q
Oct 10, 2025
Sinatra is vulnerable to ReDoS through ETag header value generation
Low
Network
Low
None
None
SummaryThere is a denial of service vulnerability in the DetailsCarefully crafted input can cause Resources
Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 94 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.1.0
4.1.1
Fixed in
4.2.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-21510
GHSA-hxx2-7vcw-mqr3
Nov 01, 2024
Sinatra vulnerable to Reliance on Untrusted Inputs in a Security Decision
Medium
Network
Low
None
Versions of the package sinatra from 0.0.0 are vulnerable to Reliance on Untrusted Inputs in a Security Decision via the X-Forwarded-Host (XFH) header. When making a request to a method with redirect applied, it is possible to trigger an Open Redirect Attack by inserting an arbitrary address into this header. If used for caching purposes, such as with servers like Nginx, or as a reverse proxy, without handling the X-Forwarded-Host header, attackers can potentially exploit Cache Poisoning or Routing-based SSRF. Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 92 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
Fixed in
4.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-45442
GHSA-2x8x-jmrp-phxw
Nov 30, 2022
Sinatra vulnerable to Reflected File Download attack
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
DescriptionAn issue was discovered in Sinatra 2.0 before 2.2.3 and 3.0 before 3.0.4. An application is vulnerable to a reflected file download (RFD) attack that sets the Content-Disposition header of a response when the filename is derived from user-supplied input. References
Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
2.0.0
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
+ 7 more Show less
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
Fixed in
2.2.3
3.0.4
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-29970
GHSA-qp49-3pvw-x4m5
May 03, 2022
sinatra does not validate expanded path matches
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Sinatra before 2.2.0 does not validate that the expanded path matches public_dir when serving static files. Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 76 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
Fixed in
2.2.0
References
Updated Nov 04, 2025 · Source: OSV.dev | ||
2.0.5
patch
4 CVEs
CVE-2025-61921
GHSA-mr3q-g2mv-mr4q
Oct 10, 2025
Sinatra is vulnerable to ReDoS through ETag header value generation
Low
Network
Low
None
None
SummaryThere is a denial of service vulnerability in the DetailsCarefully crafted input can cause Resources
Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 94 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.1.0
4.1.1
Fixed in
4.2.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-21510
GHSA-hxx2-7vcw-mqr3
Nov 01, 2024
Sinatra vulnerable to Reliance on Untrusted Inputs in a Security Decision
Medium
Network
Low
None
Versions of the package sinatra from 0.0.0 are vulnerable to Reliance on Untrusted Inputs in a Security Decision via the X-Forwarded-Host (XFH) header. When making a request to a method with redirect applied, it is possible to trigger an Open Redirect Attack by inserting an arbitrary address into this header. If used for caching purposes, such as with servers like Nginx, or as a reverse proxy, without handling the X-Forwarded-Host header, attackers can potentially exploit Cache Poisoning or Routing-based SSRF. Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 92 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
Fixed in
4.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-45442
GHSA-2x8x-jmrp-phxw
Nov 30, 2022
Sinatra vulnerable to Reflected File Download attack
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
DescriptionAn issue was discovered in Sinatra 2.0 before 2.2.3 and 3.0 before 3.0.4. An application is vulnerable to a reflected file download (RFD) attack that sets the Content-Disposition header of a response when the filename is derived from user-supplied input. References
Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
2.0.0
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
+ 7 more Show less
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
Fixed in
2.2.3
3.0.4
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-29970
GHSA-qp49-3pvw-x4m5
May 03, 2022
sinatra does not validate expanded path matches
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Sinatra before 2.2.0 does not validate that the expanded path matches public_dir when serving static files. Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 76 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
Fixed in
2.2.0
References
Updated Nov 04, 2025 · Source: OSV.dev | ||
2.0.4
patch
4 CVEs
CVE-2025-61921
GHSA-mr3q-g2mv-mr4q
Oct 10, 2025
Sinatra is vulnerable to ReDoS through ETag header value generation
Low
Network
Low
None
None
SummaryThere is a denial of service vulnerability in the DetailsCarefully crafted input can cause Resources
Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 94 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.1.0
4.1.1
Fixed in
4.2.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-21510
GHSA-hxx2-7vcw-mqr3
Nov 01, 2024
Sinatra vulnerable to Reliance on Untrusted Inputs in a Security Decision
Medium
Network
Low
None
Versions of the package sinatra from 0.0.0 are vulnerable to Reliance on Untrusted Inputs in a Security Decision via the X-Forwarded-Host (XFH) header. When making a request to a method with redirect applied, it is possible to trigger an Open Redirect Attack by inserting an arbitrary address into this header. If used for caching purposes, such as with servers like Nginx, or as a reverse proxy, without handling the X-Forwarded-Host header, attackers can potentially exploit Cache Poisoning or Routing-based SSRF. Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 92 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
Fixed in
4.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-45442
GHSA-2x8x-jmrp-phxw
Nov 30, 2022
Sinatra vulnerable to Reflected File Download attack
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
DescriptionAn issue was discovered in Sinatra 2.0 before 2.2.3 and 3.0 before 3.0.4. An application is vulnerable to a reflected file download (RFD) attack that sets the Content-Disposition header of a response when the filename is derived from user-supplied input. References
Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
2.0.0
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
+ 7 more Show less
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
Fixed in
2.2.3
3.0.4
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-29970
GHSA-qp49-3pvw-x4m5
May 03, 2022
sinatra does not validate expanded path matches
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Sinatra before 2.2.0 does not validate that the expanded path matches public_dir when serving static files. Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 76 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
Fixed in
2.2.0
References
Updated Nov 04, 2025 · Source: OSV.dev | ||
2.0.3
patch
4 CVEs
CVE-2025-61921
GHSA-mr3q-g2mv-mr4q
Oct 10, 2025
Sinatra is vulnerable to ReDoS through ETag header value generation
Low
Network
Low
None
None
SummaryThere is a denial of service vulnerability in the DetailsCarefully crafted input can cause Resources
Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 94 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.1.0
4.1.1
Fixed in
4.2.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-21510
GHSA-hxx2-7vcw-mqr3
Nov 01, 2024
Sinatra vulnerable to Reliance on Untrusted Inputs in a Security Decision
Medium
Network
Low
None
Versions of the package sinatra from 0.0.0 are vulnerable to Reliance on Untrusted Inputs in a Security Decision via the X-Forwarded-Host (XFH) header. When making a request to a method with redirect applied, it is possible to trigger an Open Redirect Attack by inserting an arbitrary address into this header. If used for caching purposes, such as with servers like Nginx, or as a reverse proxy, without handling the X-Forwarded-Host header, attackers can potentially exploit Cache Poisoning or Routing-based SSRF. Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 92 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
Fixed in
4.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-45442
GHSA-2x8x-jmrp-phxw
Nov 30, 2022
Sinatra vulnerable to Reflected File Download attack
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
DescriptionAn issue was discovered in Sinatra 2.0 before 2.2.3 and 3.0 before 3.0.4. An application is vulnerable to a reflected file download (RFD) attack that sets the Content-Disposition header of a response when the filename is derived from user-supplied input. References
Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
2.0.0
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
+ 7 more Show less
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
Fixed in
2.2.3
3.0.4
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-29970
GHSA-qp49-3pvw-x4m5
May 03, 2022
sinatra does not validate expanded path matches
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Sinatra before 2.2.0 does not validate that the expanded path matches public_dir when serving static files. Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 76 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
Fixed in
2.2.0
References
Updated Nov 04, 2025 · Source: OSV.dev | ||
2.0.2
patch
4 CVEs
CVE-2025-61921
GHSA-mr3q-g2mv-mr4q
Oct 10, 2025
Sinatra is vulnerable to ReDoS through ETag header value generation
Low
Network
Low
None
None
SummaryThere is a denial of service vulnerability in the DetailsCarefully crafted input can cause Resources
Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 94 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.1.0
4.1.1
Fixed in
4.2.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-21510
GHSA-hxx2-7vcw-mqr3
Nov 01, 2024
Sinatra vulnerable to Reliance on Untrusted Inputs in a Security Decision
Medium
Network
Low
None
Versions of the package sinatra from 0.0.0 are vulnerable to Reliance on Untrusted Inputs in a Security Decision via the X-Forwarded-Host (XFH) header. When making a request to a method with redirect applied, it is possible to trigger an Open Redirect Attack by inserting an arbitrary address into this header. If used for caching purposes, such as with servers like Nginx, or as a reverse proxy, without handling the X-Forwarded-Host header, attackers can potentially exploit Cache Poisoning or Routing-based SSRF. Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 92 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
Fixed in
4.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-45442
GHSA-2x8x-jmrp-phxw
Nov 30, 2022
Sinatra vulnerable to Reflected File Download attack
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
DescriptionAn issue was discovered in Sinatra 2.0 before 2.2.3 and 3.0 before 3.0.4. An application is vulnerable to a reflected file download (RFD) attack that sets the Content-Disposition header of a response when the filename is derived from user-supplied input. References
Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
2.0.0
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
+ 7 more Show less
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
Fixed in
2.2.3
3.0.4
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-29970
GHSA-qp49-3pvw-x4m5
May 03, 2022
sinatra does not validate expanded path matches
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Sinatra before 2.2.0 does not validate that the expanded path matches public_dir when serving static files. Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 76 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
Fixed in
2.2.0
References
Updated Nov 04, 2025 · Source: OSV.dev | ||
2.0.1
patch
5 CVEs
CVE-2025-61921
GHSA-mr3q-g2mv-mr4q
Oct 10, 2025
Sinatra is vulnerable to ReDoS through ETag header value generation
Low
Network
Low
None
None
SummaryThere is a denial of service vulnerability in the DetailsCarefully crafted input can cause Resources
Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 94 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.1.0
4.1.1
Fixed in
4.2.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-21510
GHSA-hxx2-7vcw-mqr3
Nov 01, 2024
Sinatra vulnerable to Reliance on Untrusted Inputs in a Security Decision
Medium
Network
Low
None
Versions of the package sinatra from 0.0.0 are vulnerable to Reliance on Untrusted Inputs in a Security Decision via the X-Forwarded-Host (XFH) header. When making a request to a method with redirect applied, it is possible to trigger an Open Redirect Attack by inserting an arbitrary address into this header. If used for caching purposes, such as with servers like Nginx, or as a reverse proxy, without handling the X-Forwarded-Host header, attackers can potentially exploit Cache Poisoning or Routing-based SSRF. Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 92 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
Fixed in
4.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-45442
GHSA-2x8x-jmrp-phxw
Nov 30, 2022
Sinatra vulnerable to Reflected File Download attack
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
DescriptionAn issue was discovered in Sinatra 2.0 before 2.2.3 and 3.0 before 3.0.4. An application is vulnerable to a reflected file download (RFD) attack that sets the Content-Disposition header of a response when the filename is derived from user-supplied input. References
Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
2.0.0
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
+ 7 more Show less
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
Fixed in
2.2.3
3.0.4
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-29970
GHSA-qp49-3pvw-x4m5
May 03, 2022
sinatra does not validate expanded path matches
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Sinatra before 2.2.0 does not validate that the expanded path matches public_dir when serving static files. Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 76 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
Fixed in
2.2.0
References
Updated Nov 04, 2025 · Source: OSV.dev
CVE-2018-11627
GHSA-mq35-wqvf-r23c
Jun 05, 2018
Sinatra Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Sinatra before 2.0.2 has XSS via the 400 Bad Request page that occurs upon a params parser exception. Affected versions
2.0.0
2.0.1
2.0.1.rc1
Fixed in
2.0.2
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
2.0.1.rc1
pre
6 CVEs
CVE-2025-61921
GHSA-mr3q-g2mv-mr4q
Oct 10, 2025
Sinatra is vulnerable to ReDoS through ETag header value generation
Low
Network
Low
None
None
SummaryThere is a denial of service vulnerability in the DetailsCarefully crafted input can cause Resources
Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 94 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.1.0
4.1.1
Fixed in
4.2.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-21510
GHSA-hxx2-7vcw-mqr3
Nov 01, 2024
Sinatra vulnerable to Reliance on Untrusted Inputs in a Security Decision
Medium
Network
Low
None
Versions of the package sinatra from 0.0.0 are vulnerable to Reliance on Untrusted Inputs in a Security Decision via the X-Forwarded-Host (XFH) header. When making a request to a method with redirect applied, it is possible to trigger an Open Redirect Attack by inserting an arbitrary address into this header. If used for caching purposes, such as with servers like Nginx, or as a reverse proxy, without handling the X-Forwarded-Host header, attackers can potentially exploit Cache Poisoning or Routing-based SSRF. Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 92 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
Fixed in
4.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-45442
GHSA-2x8x-jmrp-phxw
Nov 30, 2022
Sinatra vulnerable to Reflected File Download attack
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
DescriptionAn issue was discovered in Sinatra 2.0 before 2.2.3 and 3.0 before 3.0.4. An application is vulnerable to a reflected file download (RFD) attack that sets the Content-Disposition header of a response when the filename is derived from user-supplied input. References
Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
2.0.0
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
+ 7 more Show less
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
Fixed in
2.2.3
3.0.4
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-29970
GHSA-qp49-3pvw-x4m5
May 03, 2022
sinatra does not validate expanded path matches
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Sinatra before 2.2.0 does not validate that the expanded path matches public_dir when serving static files. Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 76 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
Fixed in
2.2.0
References
Updated Nov 04, 2025 · Source: OSV.dev
CVE-2018-11627
GHSA-mq35-wqvf-r23c
Jun 05, 2018
Sinatra Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Sinatra before 2.0.2 has XSS via the 400 Bad Request page that occurs upon a params parser exception. Affected versions
2.0.0
2.0.1
2.0.1.rc1
Fixed in
2.0.2
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2018-7212
GHSA-h29f-7f56-j8wh
Feb 20, 2018
Sinatra Path Traversal vulnerability
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
An issue was discovered in Affected versions
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1.rc1
Fixed in
2.0.1
References Updated Nov 08, 2023 · Source: OSV.dev | ||
2.0.0
major
6 CVEs
CVE-2025-61921
GHSA-mr3q-g2mv-mr4q
Oct 10, 2025
Sinatra is vulnerable to ReDoS through ETag header value generation
Low
Network
Low
None
None
SummaryThere is a denial of service vulnerability in the DetailsCarefully crafted input can cause Resources
Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 94 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.1.0
4.1.1
Fixed in
4.2.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-21510
GHSA-hxx2-7vcw-mqr3
Nov 01, 2024
Sinatra vulnerable to Reliance on Untrusted Inputs in a Security Decision
Medium
Network
Low
None
Versions of the package sinatra from 0.0.0 are vulnerable to Reliance on Untrusted Inputs in a Security Decision via the X-Forwarded-Host (XFH) header. When making a request to a method with redirect applied, it is possible to trigger an Open Redirect Attack by inserting an arbitrary address into this header. If used for caching purposes, such as with servers like Nginx, or as a reverse proxy, without handling the X-Forwarded-Host header, attackers can potentially exploit Cache Poisoning or Routing-based SSRF. Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 92 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
Fixed in
4.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-45442
GHSA-2x8x-jmrp-phxw
Nov 30, 2022
Sinatra vulnerable to Reflected File Download attack
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
DescriptionAn issue was discovered in Sinatra 2.0 before 2.2.3 and 3.0 before 3.0.4. An application is vulnerable to a reflected file download (RFD) attack that sets the Content-Disposition header of a response when the filename is derived from user-supplied input. References
Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
2.0.0
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
+ 7 more Show less
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
Fixed in
2.2.3
3.0.4
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-29970
GHSA-qp49-3pvw-x4m5
May 03, 2022
sinatra does not validate expanded path matches
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Sinatra before 2.2.0 does not validate that the expanded path matches public_dir when serving static files. Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 76 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
Fixed in
2.2.0
References
Updated Nov 04, 2025 · Source: OSV.dev
CVE-2018-11627
GHSA-mq35-wqvf-r23c
Jun 05, 2018
Sinatra Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Sinatra before 2.0.2 has XSS via the 400 Bad Request page that occurs upon a params parser exception. Affected versions
2.0.0
2.0.1
2.0.1.rc1
Fixed in
2.0.2
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2018-7212
GHSA-h29f-7f56-j8wh
Feb 20, 2018
Sinatra Path Traversal vulnerability
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
An issue was discovered in Affected versions
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1.rc1
Fixed in
2.0.1
References Updated Nov 08, 2023 · Source: OSV.dev | ||
2.0.0.rc6
pre
4 CVEs
CVE-2025-61921
GHSA-mr3q-g2mv-mr4q
Oct 10, 2025
Sinatra is vulnerable to ReDoS through ETag header value generation
Low
Network
Low
None
None
SummaryThere is a denial of service vulnerability in the DetailsCarefully crafted input can cause Resources
Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 94 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.1.0
4.1.1
Fixed in
4.2.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-21510
GHSA-hxx2-7vcw-mqr3
Nov 01, 2024
Sinatra vulnerable to Reliance on Untrusted Inputs in a Security Decision
Medium
Network
Low
None
Versions of the package sinatra from 0.0.0 are vulnerable to Reliance on Untrusted Inputs in a Security Decision via the X-Forwarded-Host (XFH) header. When making a request to a method with redirect applied, it is possible to trigger an Open Redirect Attack by inserting an arbitrary address into this header. If used for caching purposes, such as with servers like Nginx, or as a reverse proxy, without handling the X-Forwarded-Host header, attackers can potentially exploit Cache Poisoning or Routing-based SSRF. Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 92 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
Fixed in
4.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-29970
GHSA-qp49-3pvw-x4m5
May 03, 2022
sinatra does not validate expanded path matches
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Sinatra before 2.2.0 does not validate that the expanded path matches public_dir when serving static files. Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 76 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
Fixed in
2.2.0
References
Updated Nov 04, 2025 · Source: OSV.dev
CVE-2018-7212
GHSA-h29f-7f56-j8wh
Feb 20, 2018
Sinatra Path Traversal vulnerability
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
An issue was discovered in Affected versions
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1.rc1
Fixed in
2.0.1
References Updated Nov 08, 2023 · Source: OSV.dev | ||
2.0.0.rc5
pre
4 CVEs
CVE-2025-61921
GHSA-mr3q-g2mv-mr4q
Oct 10, 2025
Sinatra is vulnerable to ReDoS through ETag header value generation
Low
Network
Low
None
None
SummaryThere is a denial of service vulnerability in the DetailsCarefully crafted input can cause Resources
Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 94 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.1.0
4.1.1
Fixed in
4.2.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-21510
GHSA-hxx2-7vcw-mqr3
Nov 01, 2024
Sinatra vulnerable to Reliance on Untrusted Inputs in a Security Decision
Medium
Network
Low
None
Versions of the package sinatra from 0.0.0 are vulnerable to Reliance on Untrusted Inputs in a Security Decision via the X-Forwarded-Host (XFH) header. When making a request to a method with redirect applied, it is possible to trigger an Open Redirect Attack by inserting an arbitrary address into this header. If used for caching purposes, such as with servers like Nginx, or as a reverse proxy, without handling the X-Forwarded-Host header, attackers can potentially exploit Cache Poisoning or Routing-based SSRF. Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 92 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
Fixed in
4.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-29970
GHSA-qp49-3pvw-x4m5
May 03, 2022
sinatra does not validate expanded path matches
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Sinatra before 2.2.0 does not validate that the expanded path matches public_dir when serving static files. Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 76 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
Fixed in
2.2.0
References
Updated Nov 04, 2025 · Source: OSV.dev
CVE-2018-7212
GHSA-h29f-7f56-j8wh
Feb 20, 2018
Sinatra Path Traversal vulnerability
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
An issue was discovered in Affected versions
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1.rc1
Fixed in
2.0.1
References Updated Nov 08, 2023 · Source: OSV.dev | ||
2.0.0.rc2
pre
4 CVEs
CVE-2025-61921
GHSA-mr3q-g2mv-mr4q
Oct 10, 2025
Sinatra is vulnerable to ReDoS through ETag header value generation
Low
Network
Low
None
None
SummaryThere is a denial of service vulnerability in the DetailsCarefully crafted input can cause Resources
Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 94 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.1.0
4.1.1
Fixed in
4.2.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-21510
GHSA-hxx2-7vcw-mqr3
Nov 01, 2024
Sinatra vulnerable to Reliance on Untrusted Inputs in a Security Decision
Medium
Network
Low
None
Versions of the package sinatra from 0.0.0 are vulnerable to Reliance on Untrusted Inputs in a Security Decision via the X-Forwarded-Host (XFH) header. When making a request to a method with redirect applied, it is possible to trigger an Open Redirect Attack by inserting an arbitrary address into this header. If used for caching purposes, such as with servers like Nginx, or as a reverse proxy, without handling the X-Forwarded-Host header, attackers can potentially exploit Cache Poisoning or Routing-based SSRF. Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 92 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
Fixed in
4.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-29970
GHSA-qp49-3pvw-x4m5
May 03, 2022
sinatra does not validate expanded path matches
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Sinatra before 2.2.0 does not validate that the expanded path matches public_dir when serving static files. Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 76 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
Fixed in
2.2.0
References
Updated Nov 04, 2025 · Source: OSV.dev
CVE-2018-7212
GHSA-h29f-7f56-j8wh
Feb 20, 2018
Sinatra Path Traversal vulnerability
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
An issue was discovered in Affected versions
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1.rc1
Fixed in
2.0.1
References Updated Nov 08, 2023 · Source: OSV.dev | ||
2.0.0.rc1
pre
4 CVEs
CVE-2025-61921
GHSA-mr3q-g2mv-mr4q
Oct 10, 2025
Sinatra is vulnerable to ReDoS through ETag header value generation
Low
Network
Low
None
None
SummaryThere is a denial of service vulnerability in the DetailsCarefully crafted input can cause Resources
Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 94 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.1.0
4.1.1
Fixed in
4.2.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-21510
GHSA-hxx2-7vcw-mqr3
Nov 01, 2024
Sinatra vulnerable to Reliance on Untrusted Inputs in a Security Decision
Medium
Network
Low
None
Versions of the package sinatra from 0.0.0 are vulnerable to Reliance on Untrusted Inputs in a Security Decision via the X-Forwarded-Host (XFH) header. When making a request to a method with redirect applied, it is possible to trigger an Open Redirect Attack by inserting an arbitrary address into this header. If used for caching purposes, such as with servers like Nginx, or as a reverse proxy, without handling the X-Forwarded-Host header, attackers can potentially exploit Cache Poisoning or Routing-based SSRF. Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 92 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
Fixed in
4.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-29970
GHSA-qp49-3pvw-x4m5
May 03, 2022
sinatra does not validate expanded path matches
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Sinatra before 2.2.0 does not validate that the expanded path matches public_dir when serving static files. Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 76 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
Fixed in
2.2.0
References
Updated Nov 04, 2025 · Source: OSV.dev
CVE-2018-7212
GHSA-h29f-7f56-j8wh
Feb 20, 2018
Sinatra Path Traversal vulnerability
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
An issue was discovered in Affected versions
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1.rc1
Fixed in
2.0.1
References Updated Nov 08, 2023 · Source: OSV.dev | ||
1.4.8
patch
3 CVEs
CVE-2025-61921
GHSA-mr3q-g2mv-mr4q
Oct 10, 2025
Sinatra is vulnerable to ReDoS through ETag header value generation
Low
Network
Low
None
None
SummaryThere is a denial of service vulnerability in the DetailsCarefully crafted input can cause Resources
Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 94 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.1.0
4.1.1
Fixed in
4.2.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-21510
GHSA-hxx2-7vcw-mqr3
Nov 01, 2024
Sinatra vulnerable to Reliance on Untrusted Inputs in a Security Decision
Medium
Network
Low
None
Versions of the package sinatra from 0.0.0 are vulnerable to Reliance on Untrusted Inputs in a Security Decision via the X-Forwarded-Host (XFH) header. When making a request to a method with redirect applied, it is possible to trigger an Open Redirect Attack by inserting an arbitrary address into this header. If used for caching purposes, such as with servers like Nginx, or as a reverse proxy, without handling the X-Forwarded-Host header, attackers can potentially exploit Cache Poisoning or Routing-based SSRF. Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 92 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
Fixed in
4.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-29970
GHSA-qp49-3pvw-x4m5
May 03, 2022
sinatra does not validate expanded path matches
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Sinatra before 2.2.0 does not validate that the expanded path matches public_dir when serving static files. Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 76 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
Fixed in
2.2.0
References
Updated Nov 04, 2025 · Source: OSV.dev | ||
2.0.0.beta2
pre
4 CVEs
CVE-2025-61921
GHSA-mr3q-g2mv-mr4q
Oct 10, 2025
Sinatra is vulnerable to ReDoS through ETag header value generation
Low
Network
Low
None
None
SummaryThere is a denial of service vulnerability in the DetailsCarefully crafted input can cause Resources
Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 94 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.1.0
4.1.1
Fixed in
4.2.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-21510
GHSA-hxx2-7vcw-mqr3
Nov 01, 2024
Sinatra vulnerable to Reliance on Untrusted Inputs in a Security Decision
Medium
Network
Low
None
Versions of the package sinatra from 0.0.0 are vulnerable to Reliance on Untrusted Inputs in a Security Decision via the X-Forwarded-Host (XFH) header. When making a request to a method with redirect applied, it is possible to trigger an Open Redirect Attack by inserting an arbitrary address into this header. If used for caching purposes, such as with servers like Nginx, or as a reverse proxy, without handling the X-Forwarded-Host header, attackers can potentially exploit Cache Poisoning or Routing-based SSRF. Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 92 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
Fixed in
4.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-29970
GHSA-qp49-3pvw-x4m5
May 03, 2022
sinatra does not validate expanded path matches
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Sinatra before 2.2.0 does not validate that the expanded path matches public_dir when serving static files. Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 76 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
Fixed in
2.2.0
References
Updated Nov 04, 2025 · Source: OSV.dev
CVE-2018-7212
GHSA-h29f-7f56-j8wh
Feb 20, 2018
Sinatra Path Traversal vulnerability
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
An issue was discovered in Affected versions
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1.rc1
Fixed in
2.0.1
References Updated Nov 08, 2023 · Source: OSV.dev | ||
2.0.0.beta1
pre
4 CVEs
CVE-2025-61921
GHSA-mr3q-g2mv-mr4q
Oct 10, 2025
Sinatra is vulnerable to ReDoS through ETag header value generation
Low
Network
Low
None
None
SummaryThere is a denial of service vulnerability in the DetailsCarefully crafted input can cause Resources
Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 94 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.1.0
4.1.1
Fixed in
4.2.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-21510
GHSA-hxx2-7vcw-mqr3
Nov 01, 2024
Sinatra vulnerable to Reliance on Untrusted Inputs in a Security Decision
Medium
Network
Low
None
Versions of the package sinatra from 0.0.0 are vulnerable to Reliance on Untrusted Inputs in a Security Decision via the X-Forwarded-Host (XFH) header. When making a request to a method with redirect applied, it is possible to trigger an Open Redirect Attack by inserting an arbitrary address into this header. If used for caching purposes, such as with servers like Nginx, or as a reverse proxy, without handling the X-Forwarded-Host header, attackers can potentially exploit Cache Poisoning or Routing-based SSRF. Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 92 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
Fixed in
4.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-29970
GHSA-qp49-3pvw-x4m5
May 03, 2022
sinatra does not validate expanded path matches
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Sinatra before 2.2.0 does not validate that the expanded path matches public_dir when serving static files. Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 76 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
Fixed in
2.2.0
References
Updated Nov 04, 2025 · Source: OSV.dev
CVE-2018-7212
GHSA-h29f-7f56-j8wh
Feb 20, 2018
Sinatra Path Traversal vulnerability
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
An issue was discovered in Affected versions
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1.rc1
Fixed in
2.0.1
References Updated Nov 08, 2023 · Source: OSV.dev | ||
1.4.7
patch
3 CVEs
CVE-2025-61921
GHSA-mr3q-g2mv-mr4q
Oct 10, 2025
Sinatra is vulnerable to ReDoS through ETag header value generation
Low
Network
Low
None
None
SummaryThere is a denial of service vulnerability in the DetailsCarefully crafted input can cause Resources
Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 94 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.1.0
4.1.1
Fixed in
4.2.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-21510
GHSA-hxx2-7vcw-mqr3
Nov 01, 2024
Sinatra vulnerable to Reliance on Untrusted Inputs in a Security Decision
Medium
Network
Low
None
Versions of the package sinatra from 0.0.0 are vulnerable to Reliance on Untrusted Inputs in a Security Decision via the X-Forwarded-Host (XFH) header. When making a request to a method with redirect applied, it is possible to trigger an Open Redirect Attack by inserting an arbitrary address into this header. If used for caching purposes, such as with servers like Nginx, or as a reverse proxy, without handling the X-Forwarded-Host header, attackers can potentially exploit Cache Poisoning or Routing-based SSRF. Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 92 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
Fixed in
4.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-29970
GHSA-qp49-3pvw-x4m5
May 03, 2022
sinatra does not validate expanded path matches
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Sinatra before 2.2.0 does not validate that the expanded path matches public_dir when serving static files. Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 76 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
Fixed in
2.2.0
References
Updated Nov 04, 2025 · Source: OSV.dev | ||
1.4.6
patch
3 CVEs
CVE-2025-61921
GHSA-mr3q-g2mv-mr4q
Oct 10, 2025
Sinatra is vulnerable to ReDoS through ETag header value generation
Low
Network
Low
None
None
SummaryThere is a denial of service vulnerability in the DetailsCarefully crafted input can cause Resources
Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 94 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.1.0
4.1.1
Fixed in
4.2.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-21510
GHSA-hxx2-7vcw-mqr3
Nov 01, 2024
Sinatra vulnerable to Reliance on Untrusted Inputs in a Security Decision
Medium
Network
Low
None
Versions of the package sinatra from 0.0.0 are vulnerable to Reliance on Untrusted Inputs in a Security Decision via the X-Forwarded-Host (XFH) header. When making a request to a method with redirect applied, it is possible to trigger an Open Redirect Attack by inserting an arbitrary address into this header. If used for caching purposes, such as with servers like Nginx, or as a reverse proxy, without handling the X-Forwarded-Host header, attackers can potentially exploit Cache Poisoning or Routing-based SSRF. Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 92 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
Fixed in
4.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-29970
GHSA-qp49-3pvw-x4m5
May 03, 2022
sinatra does not validate expanded path matches
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Sinatra before 2.2.0 does not validate that the expanded path matches public_dir when serving static files. Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 76 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
Fixed in
2.2.0
References
Updated Nov 04, 2025 · Source: OSV.dev | ||
1.4.5
patch
3 CVEs
CVE-2025-61921
GHSA-mr3q-g2mv-mr4q
Oct 10, 2025
Sinatra is vulnerable to ReDoS through ETag header value generation
Low
Network
Low
None
None
SummaryThere is a denial of service vulnerability in the DetailsCarefully crafted input can cause Resources
Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 94 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.1.0
4.1.1
Fixed in
4.2.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-21510
GHSA-hxx2-7vcw-mqr3
Nov 01, 2024
Sinatra vulnerable to Reliance on Untrusted Inputs in a Security Decision
Medium
Network
Low
None
Versions of the package sinatra from 0.0.0 are vulnerable to Reliance on Untrusted Inputs in a Security Decision via the X-Forwarded-Host (XFH) header. When making a request to a method with redirect applied, it is possible to trigger an Open Redirect Attack by inserting an arbitrary address into this header. If used for caching purposes, such as with servers like Nginx, or as a reverse proxy, without handling the X-Forwarded-Host header, attackers can potentially exploit Cache Poisoning or Routing-based SSRF. Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 92 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
Fixed in
4.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-29970
GHSA-qp49-3pvw-x4m5
May 03, 2022
sinatra does not validate expanded path matches
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Sinatra before 2.2.0 does not validate that the expanded path matches public_dir when serving static files. Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 76 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
Fixed in
2.2.0
References
Updated Nov 04, 2025 · Source: OSV.dev | ||
1.4.4
patch
3 CVEs
CVE-2025-61921
GHSA-mr3q-g2mv-mr4q
Oct 10, 2025
Sinatra is vulnerable to ReDoS through ETag header value generation
Low
Network
Low
None
None
SummaryThere is a denial of service vulnerability in the DetailsCarefully crafted input can cause Resources
Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 94 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.1.0
4.1.1
Fixed in
4.2.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-21510
GHSA-hxx2-7vcw-mqr3
Nov 01, 2024
Sinatra vulnerable to Reliance on Untrusted Inputs in a Security Decision
Medium
Network
Low
None
Versions of the package sinatra from 0.0.0 are vulnerable to Reliance on Untrusted Inputs in a Security Decision via the X-Forwarded-Host (XFH) header. When making a request to a method with redirect applied, it is possible to trigger an Open Redirect Attack by inserting an arbitrary address into this header. If used for caching purposes, such as with servers like Nginx, or as a reverse proxy, without handling the X-Forwarded-Host header, attackers can potentially exploit Cache Poisoning or Routing-based SSRF. Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 92 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
Fixed in
4.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-29970
GHSA-qp49-3pvw-x4m5
May 03, 2022
sinatra does not validate expanded path matches
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Sinatra before 2.2.0 does not validate that the expanded path matches public_dir when serving static files. Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 76 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
Fixed in
2.2.0
References
Updated Nov 04, 2025 · Source: OSV.dev | ||
1.4.3
patch
3 CVEs
CVE-2025-61921
GHSA-mr3q-g2mv-mr4q
Oct 10, 2025
Sinatra is vulnerable to ReDoS through ETag header value generation
Low
Network
Low
None
None
SummaryThere is a denial of service vulnerability in the DetailsCarefully crafted input can cause Resources
Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 94 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.1.0
4.1.1
Fixed in
4.2.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-21510
GHSA-hxx2-7vcw-mqr3
Nov 01, 2024
Sinatra vulnerable to Reliance on Untrusted Inputs in a Security Decision
Medium
Network
Low
None
Versions of the package sinatra from 0.0.0 are vulnerable to Reliance on Untrusted Inputs in a Security Decision via the X-Forwarded-Host (XFH) header. When making a request to a method with redirect applied, it is possible to trigger an Open Redirect Attack by inserting an arbitrary address into this header. If used for caching purposes, such as with servers like Nginx, or as a reverse proxy, without handling the X-Forwarded-Host header, attackers can potentially exploit Cache Poisoning or Routing-based SSRF. Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 92 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
Fixed in
4.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-29970
GHSA-qp49-3pvw-x4m5
May 03, 2022
sinatra does not validate expanded path matches
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Sinatra before 2.2.0 does not validate that the expanded path matches public_dir when serving static files. Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 76 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
Fixed in
2.2.0
References
Updated Nov 04, 2025 · Source: OSV.dev | ||
1.4.2
patch
3 CVEs
CVE-2025-61921
GHSA-mr3q-g2mv-mr4q
Oct 10, 2025
Sinatra is vulnerable to ReDoS through ETag header value generation
Low
Network
Low
None
None
SummaryThere is a denial of service vulnerability in the DetailsCarefully crafted input can cause Resources
Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 94 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.1.0
4.1.1
Fixed in
4.2.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-21510
GHSA-hxx2-7vcw-mqr3
Nov 01, 2024
Sinatra vulnerable to Reliance on Untrusted Inputs in a Security Decision
Medium
Network
Low
None
Versions of the package sinatra from 0.0.0 are vulnerable to Reliance on Untrusted Inputs in a Security Decision via the X-Forwarded-Host (XFH) header. When making a request to a method with redirect applied, it is possible to trigger an Open Redirect Attack by inserting an arbitrary address into this header. If used for caching purposes, such as with servers like Nginx, or as a reverse proxy, without handling the X-Forwarded-Host header, attackers can potentially exploit Cache Poisoning or Routing-based SSRF. Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 92 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
Fixed in
4.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-29970
GHSA-qp49-3pvw-x4m5
May 03, 2022
sinatra does not validate expanded path matches
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Sinatra before 2.2.0 does not validate that the expanded path matches public_dir when serving static files. Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 76 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
Fixed in
2.2.0
References
Updated Nov 04, 2025 · Source: OSV.dev | ||
1.4.1
patch
3 CVEs
CVE-2025-61921
GHSA-mr3q-g2mv-mr4q
Oct 10, 2025
Sinatra is vulnerable to ReDoS through ETag header value generation
Low
Network
Low
None
None
SummaryThere is a denial of service vulnerability in the DetailsCarefully crafted input can cause Resources
Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 94 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.1.0
4.1.1
Fixed in
4.2.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-21510
GHSA-hxx2-7vcw-mqr3
Nov 01, 2024
Sinatra vulnerable to Reliance on Untrusted Inputs in a Security Decision
Medium
Network
Low
None
Versions of the package sinatra from 0.0.0 are vulnerable to Reliance on Untrusted Inputs in a Security Decision via the X-Forwarded-Host (XFH) header. When making a request to a method with redirect applied, it is possible to trigger an Open Redirect Attack by inserting an arbitrary address into this header. If used for caching purposes, such as with servers like Nginx, or as a reverse proxy, without handling the X-Forwarded-Host header, attackers can potentially exploit Cache Poisoning or Routing-based SSRF. Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 92 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
Fixed in
4.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-29970
GHSA-qp49-3pvw-x4m5
May 03, 2022
sinatra does not validate expanded path matches
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Sinatra before 2.2.0 does not validate that the expanded path matches public_dir when serving static files. Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 76 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
Fixed in
2.2.0
References
Updated Nov 04, 2025 · Source: OSV.dev | ||
1.3.6
patch
3 CVEs
CVE-2025-61921
GHSA-mr3q-g2mv-mr4q
Oct 10, 2025
Sinatra is vulnerable to ReDoS through ETag header value generation
Low
Network
Low
None
None
SummaryThere is a denial of service vulnerability in the DetailsCarefully crafted input can cause Resources
Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 94 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.1.0
4.1.1
Fixed in
4.2.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-21510
GHSA-hxx2-7vcw-mqr3
Nov 01, 2024
Sinatra vulnerable to Reliance on Untrusted Inputs in a Security Decision
Medium
Network
Low
None
Versions of the package sinatra from 0.0.0 are vulnerable to Reliance on Untrusted Inputs in a Security Decision via the X-Forwarded-Host (XFH) header. When making a request to a method with redirect applied, it is possible to trigger an Open Redirect Attack by inserting an arbitrary address into this header. If used for caching purposes, such as with servers like Nginx, or as a reverse proxy, without handling the X-Forwarded-Host header, attackers can potentially exploit Cache Poisoning or Routing-based SSRF. Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 92 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
Fixed in
4.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-29970
GHSA-qp49-3pvw-x4m5
May 03, 2022
sinatra does not validate expanded path matches
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Sinatra before 2.2.0 does not validate that the expanded path matches public_dir when serving static files. Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 76 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
Fixed in
2.2.0
References
Updated Nov 04, 2025 · Source: OSV.dev | ||
1.4.0
minor
3 CVEs
CVE-2025-61921
GHSA-mr3q-g2mv-mr4q
Oct 10, 2025
Sinatra is vulnerable to ReDoS through ETag header value generation
Low
Network
Low
None
None
SummaryThere is a denial of service vulnerability in the DetailsCarefully crafted input can cause Resources
Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 94 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.1.0
4.1.1
Fixed in
4.2.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-21510
GHSA-hxx2-7vcw-mqr3
Nov 01, 2024
Sinatra vulnerable to Reliance on Untrusted Inputs in a Security Decision
Medium
Network
Low
None
Versions of the package sinatra from 0.0.0 are vulnerable to Reliance on Untrusted Inputs in a Security Decision via the X-Forwarded-Host (XFH) header. When making a request to a method with redirect applied, it is possible to trigger an Open Redirect Attack by inserting an arbitrary address into this header. If used for caching purposes, such as with servers like Nginx, or as a reverse proxy, without handling the X-Forwarded-Host header, attackers can potentially exploit Cache Poisoning or Routing-based SSRF. Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 92 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
Fixed in
4.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-29970
GHSA-qp49-3pvw-x4m5
May 03, 2022
sinatra does not validate expanded path matches
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Sinatra before 2.2.0 does not validate that the expanded path matches public_dir when serving static files. Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 76 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
Fixed in
2.2.0
References
Updated Nov 04, 2025 · Source: OSV.dev | ||
1.2.9
patch
3 CVEs
CVE-2025-61921
GHSA-mr3q-g2mv-mr4q
Oct 10, 2025
Sinatra is vulnerable to ReDoS through ETag header value generation
Low
Network
Low
None
None
SummaryThere is a denial of service vulnerability in the DetailsCarefully crafted input can cause Resources
Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 94 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.1.0
4.1.1
Fixed in
4.2.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-21510
GHSA-hxx2-7vcw-mqr3
Nov 01, 2024
Sinatra vulnerable to Reliance on Untrusted Inputs in a Security Decision
Medium
Network
Low
None
Versions of the package sinatra from 0.0.0 are vulnerable to Reliance on Untrusted Inputs in a Security Decision via the X-Forwarded-Host (XFH) header. When making a request to a method with redirect applied, it is possible to trigger an Open Redirect Attack by inserting an arbitrary address into this header. If used for caching purposes, such as with servers like Nginx, or as a reverse proxy, without handling the X-Forwarded-Host header, attackers can potentially exploit Cache Poisoning or Routing-based SSRF. Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 92 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
Fixed in
4.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-29970
GHSA-qp49-3pvw-x4m5
May 03, 2022
sinatra does not validate expanded path matches
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Sinatra before 2.2.0 does not validate that the expanded path matches public_dir when serving static files. Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 76 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
Fixed in
2.2.0
References
Updated Nov 04, 2025 · Source: OSV.dev | ||
1.4.0.d
pre
3 CVEs
CVE-2025-61921
GHSA-mr3q-g2mv-mr4q
Oct 10, 2025
Sinatra is vulnerable to ReDoS through ETag header value generation
Low
Network
Low
None
None
SummaryThere is a denial of service vulnerability in the DetailsCarefully crafted input can cause Resources
Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 94 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.1.0
4.1.1
Fixed in
4.2.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-21510
GHSA-hxx2-7vcw-mqr3
Nov 01, 2024
Sinatra vulnerable to Reliance on Untrusted Inputs in a Security Decision
Medium
Network
Low
None
Versions of the package sinatra from 0.0.0 are vulnerable to Reliance on Untrusted Inputs in a Security Decision via the X-Forwarded-Host (XFH) header. When making a request to a method with redirect applied, it is possible to trigger an Open Redirect Attack by inserting an arbitrary address into this header. If used for caching purposes, such as with servers like Nginx, or as a reverse proxy, without handling the X-Forwarded-Host header, attackers can potentially exploit Cache Poisoning or Routing-based SSRF. Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 92 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
Fixed in
4.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-29970
GHSA-qp49-3pvw-x4m5
May 03, 2022
sinatra does not validate expanded path matches
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Sinatra before 2.2.0 does not validate that the expanded path matches public_dir when serving static files. Affected versions
0.1.0
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.9.0
+ 76 more Show less
0.9.0.1
0.9.0.2
0.9.0.3
0.9.0.4
0.9.0.5
0.9.1
0.9.1.1
0.9.2
0.9.4
0.9.5
0.9.6
1.0
1.0.a
1.0.b
1.1.0
1.1.2
1.1.3
1.1.4
1.1.a
1.1.b
1.2.0
1.2.0.a
1.2.0.c
1.2.0.d
1.2.1
1.2.2
1.2.3
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0.a
1.3.0.b
1.3.0.c
1.3.0.d
1.3.0.e
1.3.0.f
1.3.0.g
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.a
1.4.0.b
1.4.0.c
1.4.0.d
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
2.0.0
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
2.0.1
2.0.1.rc1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.8.1
2.1.0
Fixed in
2.2.0
References
Updated Nov 04, 2025 · Source: OSV.dev |