Skip to main content

Vendor/product archive

ruby-lang / uri CVEs

Beta · best-effort

4 CVEs tagged to ruby-lang / uri0 Critical, 0 High, 2 Medium, 2 Low, 0 Unrated.

CVE-2025-61594

Published Dec 30, 2025

URI is a module providing classes to handle Uniform Resource Identifiers. In versions 0.12.4 and earlier (bundled in Ruby 3.2 series) 0.13.2 and earlier (bundled in Ruby 3.3 serie…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-27221

Published Mar 4, 2025

In the URI gem before 1.0.3 for Ruby, the URI handling methods (URI.join, URI#merge, URI#+) have an inadvertent leakage of authentication credentials because userinfo is retained…

CVSS 3.2 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-36617

Published Jun 29, 2023

A ReDoS issue was discovered in the URI component before 0.12.2 for Ruby. The URI parser mishandles invalid URLs that have specific characters. There is an increase in execution t…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-4 of 4 CVEsPage 1 of 1