We found results for “”
CVE-2025-61594
Good to know:
Date: December 30, 2025
URI is a module providing classes to handle Uniform Resource Identifiers. In versions prior to 0.12.5, 0.13.3, and 1.0.4, a bypass exists for the fix to CVE-2025-27221 that can expose user credentials. When using the "+" operator to combine URIs, sensitive information like passwords from the original URI can be leaked, violating RFC3986 and making applications vulnerable to credential exposure. Versions 0.12.5, 0.13.3, and 1.0.4 fix the issue.
Severity Score
Related Resources (9)
Severity Score
Weakness Type (CWE)
Improper Removal of Sensitive Information Before Storage or Transfer
CWE-212Top Fix
Upgrade Version
Upgrade to version uri - 0.12.5;uri - 0.13.3;uri - 1.0.4;https://github.com/ruby/uri.git - v1.0.4;https://github.com/ruby/uri.git - v0.13.3;https://github.com/ruby/uri.git - v0.12.5
CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | NETWORK |
| Attack Complexity (AC): | LOW |
| Privileges Required (PR): | NONE |
| User Interaction (UI): | NONE |
| Scope (S): | UNCHANGED |
| Confidentiality (C): | LOW |
| Integrity (I): | NONE |
| Availability (A): | NONE |
Vulnerabilities
Projects
Contact Us


