Skip to main content

Vendor/product archive

carrierwave_project / carrierwave CVEs

Beta · best-effort

5 CVEs tagged to carrierwave_project / carrierwave0 Critical, 1 High, 4 Medium, 0 Low, 0 Unrated.

CVE-2026-44587

Published Jun 17, 2026

CarrierWave is a framework to upload files from Ruby applications. In versions prior to 2.2.7 and 3.1.3, the content_type_denylist check fails to escape regex metacharacters in st…

CVSS 4.7 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2024-29034

Published Mar 24, 2024

CarrierWave is a solution for file uploads for Rails, Sinatra and other Ruby web frameworks. The vulnerability CVE-2023-49090 wasn't fully addressed. This vulnerability is caused…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-49090

Published Nov 29, 2023

CarrierWave is a solution for file uploads for Rails, Sinatra and other Ruby web frameworks. CarrierWave has a Content-Type allowlist bypass vulnerability, possibly leading to XSS…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-21305

Published Feb 8, 2021

CarrierWave is an open-source RubyGem which provides a simple and flexible way to upload files from Ruby applications. In CarrierWave before versions 1.3.2 and 2.1.1, there is a c…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2021-21288

Published Feb 8, 2021

CarrierWave is an open-source RubyGem which provides a simple and flexible way to upload files from Ruby applications. In CarrierWave before versions 1.3.2 and 2.1.1 the download…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-5 of 5 CVEsPage 1 of 1