httparty
Makes http fun! Also, makes consuming restful web services dead easy.
Activity
- Latest release
- 8mo ago
- Total releases
- 87
- Cadence
- ~2 months
- Last 12 months
- 4
Reach
- Stars
- —
Details
- License
- MIT
- First release
- Jul 29, 2008
| Version | Released | |
|---|---|---|
0.24.1
patch
| ||
0.24.2
patch
| ||
0.24.0
minor
| ||
0.23.2
patch
1 CVE
CVE-2025-68696
GHSA-hm5p-x4rq-38w4
Dec 23, 2025
httparty Has Potential SSRF Vulnerability That Leads to API Key Leakage
High
Network
Low
None
None
SummaryThere may be an SSRF vulnerability in httparty. This issue can pose a risk of leaking API keys, and it can also allow third parties to issue requests to internal servers. DetailsWhen httparty receives a path argument that is an absolute URL, it ignores the Consider the following example of a web application:
Now, suppose an attacker sends a request like this:
In this case, httparty sends the A similar problem was reported and fixed in the HTTP client library axios in the past: Also, Python's PoCFollow these steps to reproduce the issue:
Although Impact
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
0.1.8
0.10.0
0.10.1
0.10.2
0.11.0
+ 72 more Show less
0.12.0
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.15.7
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.0
0.17.1
0.17.3
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.7.0
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
Fixed in
0.24.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.23.1
patch
1 CVE
CVE-2025-68696
GHSA-hm5p-x4rq-38w4
Dec 23, 2025
httparty Has Potential SSRF Vulnerability That Leads to API Key Leakage
High
Network
Low
None
None
SummaryThere may be an SSRF vulnerability in httparty. This issue can pose a risk of leaking API keys, and it can also allow third parties to issue requests to internal servers. DetailsWhen httparty receives a path argument that is an absolute URL, it ignores the Consider the following example of a web application:
Now, suppose an attacker sends a request like this:
In this case, httparty sends the A similar problem was reported and fixed in the HTTP client library axios in the past: Also, Python's PoCFollow these steps to reproduce the issue:
Although Impact
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
0.1.8
0.10.0
0.10.1
0.10.2
0.11.0
+ 72 more Show less
0.12.0
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.15.7
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.0
0.17.1
0.17.3
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.7.0
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
Fixed in
0.24.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.23.0
minor
1 CVE
CVE-2025-68696
GHSA-hm5p-x4rq-38w4
Dec 23, 2025
httparty Has Potential SSRF Vulnerability That Leads to API Key Leakage
High
Network
Low
None
None
SummaryThere may be an SSRF vulnerability in httparty. This issue can pose a risk of leaking API keys, and it can also allow third parties to issue requests to internal servers. DetailsWhen httparty receives a path argument that is an absolute URL, it ignores the Consider the following example of a web application:
Now, suppose an attacker sends a request like this:
In this case, httparty sends the A similar problem was reported and fixed in the HTTP client library axios in the past: Also, Python's PoCFollow these steps to reproduce the issue:
Although Impact
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
0.1.8
0.10.0
0.10.1
0.10.2
0.11.0
+ 72 more Show less
0.12.0
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.15.7
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.0
0.17.1
0.17.3
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.7.0
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
Fixed in
0.24.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.22.0
minor
1 CVE
CVE-2025-68696
GHSA-hm5p-x4rq-38w4
Dec 23, 2025
httparty Has Potential SSRF Vulnerability That Leads to API Key Leakage
High
Network
Low
None
None
SummaryThere may be an SSRF vulnerability in httparty. This issue can pose a risk of leaking API keys, and it can also allow third parties to issue requests to internal servers. DetailsWhen httparty receives a path argument that is an absolute URL, it ignores the Consider the following example of a web application:
Now, suppose an attacker sends a request like this:
In this case, httparty sends the A similar problem was reported and fixed in the HTTP client library axios in the past: Also, Python's PoCFollow these steps to reproduce the issue:
Although Impact
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
0.1.8
0.10.0
0.10.1
0.10.2
0.11.0
+ 72 more Show less
0.12.0
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.15.7
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.0
0.17.1
0.17.3
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.7.0
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
Fixed in
0.24.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.21.0
minor
1 CVE
CVE-2025-68696
GHSA-hm5p-x4rq-38w4
Dec 23, 2025
httparty Has Potential SSRF Vulnerability That Leads to API Key Leakage
High
Network
Low
None
None
SummaryThere may be an SSRF vulnerability in httparty. This issue can pose a risk of leaking API keys, and it can also allow third parties to issue requests to internal servers. DetailsWhen httparty receives a path argument that is an absolute URL, it ignores the Consider the following example of a web application:
Now, suppose an attacker sends a request like this:
In this case, httparty sends the A similar problem was reported and fixed in the HTTP client library axios in the past: Also, Python's PoCFollow these steps to reproduce the issue:
Although Impact
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
0.1.8
0.10.0
0.10.1
0.10.2
0.11.0
+ 72 more Show less
0.12.0
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.15.7
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.0
0.17.1
0.17.3
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.7.0
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
Fixed in
0.24.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.19.1
patch
2 CVEs
CVE-2025-68696
GHSA-hm5p-x4rq-38w4
Dec 23, 2025
httparty Has Potential SSRF Vulnerability That Leads to API Key Leakage
High
Network
Low
None
None
SummaryThere may be an SSRF vulnerability in httparty. This issue can pose a risk of leaking API keys, and it can also allow third parties to issue requests to internal servers. DetailsWhen httparty receives a path argument that is an absolute URL, it ignores the Consider the following example of a web application:
Now, suppose an attacker sends a request like this:
In this case, httparty sends the A similar problem was reported and fixed in the HTTP client library axios in the past: Also, Python's PoCFollow these steps to reproduce the issue:
Although Impact
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
0.1.8
0.10.0
0.10.1
0.10.2
0.11.0
+ 72 more Show less
0.12.0
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.15.7
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.0
0.17.1
0.17.3
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.7.0
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
Fixed in
0.24.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-22049
GHSA-5pq7-52mg-hr42
Jan 03, 2023
httparty has multipart/form-data request tampering vulnerability
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
ImpactI found "multipart/form-data request tampering vulnerability" caused by Content-Disposition "filename" lack of escaping in httparty.
https://github.com/jnunemaker/httparty/blob/4416141d37fd71bdba4f37589ec265f55aa446ce/lib/httparty/request/body.rb#L43 By exploiting this problem, the following attacks are possible
For example, this vulnerability can be exploited to generate the following Content-Disposition.
The Abused Header has multiple name ( These problems can result in successful or unsuccessful attacks, depending on the behavior of the parser receiving the request. I have confirmed that the attack succeeds, at least in the following frameworks
The cause of this problem is the lack of escaping of the WhatWG's HTML spec has an escaping requirement. https://html.spec.whatwg.org/#multipart-form-data
PatchesAs noted at the beginning of this section, encoding must be done as described in the HTML Spec. https://html.spec.whatwg.org/#multipart-form-data
Therefore, it is recommended that Content-Disposition be modified by either of the following
https://github.com/jnunemaker/httparty/blob/4416141d37fd71bdba4f37589ec265f55aa446ce/lib/httparty/request/body.rb#L43
Also, as for PoCPoC EnvironmentOS: macOS Monterey(12.3) Ruby ver: ruby 3.1.2p20 httparty ver: 0.20.0 (Python3 - HTTP Request Logging Server) PoC procedure(Linux or MacOS is required.
This is because Windows does not allow file names containing
I write Python code, but any method will work as long as you can see the HTTP Request Body. (e.g. Debugger, HTTP Logging Server, Packet Capture) $ vi logging.py
$ python logging.py
Return Request Header & Body:
Content-Disposition:
References
Golang https://github.com/golang/go/blob/e0e0c8fe9881bbbfe689ad94ca5dddbb252e4233/src/mime/multipart/writer.go#L144 Spring https://github.com/spring-projects/spring-framework/blob/4cc91e46b210b4e4e7ed182f93994511391b54ed/spring-web/src/main/java/org/springframework/http/ContentDisposition.java#L259-L267 Symphony https://github.com/symfony/symfony/blob/123b1651c4a7e219ba59074441badfac65525efe/src/Symfony/Component/Mime/Header/ParameterizedHeader.php#L128-L133 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
0.1.8
0.10.0
0.10.1
0.10.2
0.11.0
+ 67 more Show less
0.12.0
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.15.7
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.0
0.17.1
0.17.3
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.7.0
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
Fixed in
0.21.0
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.20.0
minor
2 CVEs
CVE-2025-68696
GHSA-hm5p-x4rq-38w4
Dec 23, 2025
httparty Has Potential SSRF Vulnerability That Leads to API Key Leakage
High
Network
Low
None
None
SummaryThere may be an SSRF vulnerability in httparty. This issue can pose a risk of leaking API keys, and it can also allow third parties to issue requests to internal servers. DetailsWhen httparty receives a path argument that is an absolute URL, it ignores the Consider the following example of a web application:
Now, suppose an attacker sends a request like this:
In this case, httparty sends the A similar problem was reported and fixed in the HTTP client library axios in the past: Also, Python's PoCFollow these steps to reproduce the issue:
Although Impact
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
0.1.8
0.10.0
0.10.1
0.10.2
0.11.0
+ 72 more Show less
0.12.0
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.15.7
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.0
0.17.1
0.17.3
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.7.0
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
Fixed in
0.24.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-22049
GHSA-5pq7-52mg-hr42
Jan 03, 2023
httparty has multipart/form-data request tampering vulnerability
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
ImpactI found "multipart/form-data request tampering vulnerability" caused by Content-Disposition "filename" lack of escaping in httparty.
https://github.com/jnunemaker/httparty/blob/4416141d37fd71bdba4f37589ec265f55aa446ce/lib/httparty/request/body.rb#L43 By exploiting this problem, the following attacks are possible
For example, this vulnerability can be exploited to generate the following Content-Disposition.
The Abused Header has multiple name ( These problems can result in successful or unsuccessful attacks, depending on the behavior of the parser receiving the request. I have confirmed that the attack succeeds, at least in the following frameworks
The cause of this problem is the lack of escaping of the WhatWG's HTML spec has an escaping requirement. https://html.spec.whatwg.org/#multipart-form-data
PatchesAs noted at the beginning of this section, encoding must be done as described in the HTML Spec. https://html.spec.whatwg.org/#multipart-form-data
Therefore, it is recommended that Content-Disposition be modified by either of the following
https://github.com/jnunemaker/httparty/blob/4416141d37fd71bdba4f37589ec265f55aa446ce/lib/httparty/request/body.rb#L43
Also, as for PoCPoC EnvironmentOS: macOS Monterey(12.3) Ruby ver: ruby 3.1.2p20 httparty ver: 0.20.0 (Python3 - HTTP Request Logging Server) PoC procedure(Linux or MacOS is required.
This is because Windows does not allow file names containing
I write Python code, but any method will work as long as you can see the HTTP Request Body. (e.g. Debugger, HTTP Logging Server, Packet Capture) $ vi logging.py
$ python logging.py
Return Request Header & Body:
Content-Disposition:
References
Golang https://github.com/golang/go/blob/e0e0c8fe9881bbbfe689ad94ca5dddbb252e4233/src/mime/multipart/writer.go#L144 Spring https://github.com/spring-projects/spring-framework/blob/4cc91e46b210b4e4e7ed182f93994511391b54ed/spring-web/src/main/java/org/springframework/http/ContentDisposition.java#L259-L267 Symphony https://github.com/symfony/symfony/blob/123b1651c4a7e219ba59074441badfac65525efe/src/Symfony/Component/Mime/Header/ParameterizedHeader.php#L128-L133 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
0.1.8
0.10.0
0.10.1
0.10.2
0.11.0
+ 67 more Show less
0.12.0
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.15.7
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.0
0.17.1
0.17.3
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.7.0
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
Fixed in
0.21.0
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.19.0
minor
2 CVEs
CVE-2025-68696
GHSA-hm5p-x4rq-38w4
Dec 23, 2025
httparty Has Potential SSRF Vulnerability That Leads to API Key Leakage
High
Network
Low
None
None
SummaryThere may be an SSRF vulnerability in httparty. This issue can pose a risk of leaking API keys, and it can also allow third parties to issue requests to internal servers. DetailsWhen httparty receives a path argument that is an absolute URL, it ignores the Consider the following example of a web application:
Now, suppose an attacker sends a request like this:
In this case, httparty sends the A similar problem was reported and fixed in the HTTP client library axios in the past: Also, Python's PoCFollow these steps to reproduce the issue:
Although Impact
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
0.1.8
0.10.0
0.10.1
0.10.2
0.11.0
+ 72 more Show less
0.12.0
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.15.7
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.0
0.17.1
0.17.3
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.7.0
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
Fixed in
0.24.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-22049
GHSA-5pq7-52mg-hr42
Jan 03, 2023
httparty has multipart/form-data request tampering vulnerability
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
ImpactI found "multipart/form-data request tampering vulnerability" caused by Content-Disposition "filename" lack of escaping in httparty.
https://github.com/jnunemaker/httparty/blob/4416141d37fd71bdba4f37589ec265f55aa446ce/lib/httparty/request/body.rb#L43 By exploiting this problem, the following attacks are possible
For example, this vulnerability can be exploited to generate the following Content-Disposition.
The Abused Header has multiple name ( These problems can result in successful or unsuccessful attacks, depending on the behavior of the parser receiving the request. I have confirmed that the attack succeeds, at least in the following frameworks
The cause of this problem is the lack of escaping of the WhatWG's HTML spec has an escaping requirement. https://html.spec.whatwg.org/#multipart-form-data
PatchesAs noted at the beginning of this section, encoding must be done as described in the HTML Spec. https://html.spec.whatwg.org/#multipart-form-data
Therefore, it is recommended that Content-Disposition be modified by either of the following
https://github.com/jnunemaker/httparty/blob/4416141d37fd71bdba4f37589ec265f55aa446ce/lib/httparty/request/body.rb#L43
Also, as for PoCPoC EnvironmentOS: macOS Monterey(12.3) Ruby ver: ruby 3.1.2p20 httparty ver: 0.20.0 (Python3 - HTTP Request Logging Server) PoC procedure(Linux or MacOS is required.
This is because Windows does not allow file names containing
I write Python code, but any method will work as long as you can see the HTTP Request Body. (e.g. Debugger, HTTP Logging Server, Packet Capture) $ vi logging.py
$ python logging.py
Return Request Header & Body:
Content-Disposition:
References
Golang https://github.com/golang/go/blob/e0e0c8fe9881bbbfe689ad94ca5dddbb252e4233/src/mime/multipart/writer.go#L144 Spring https://github.com/spring-projects/spring-framework/blob/4cc91e46b210b4e4e7ed182f93994511391b54ed/spring-web/src/main/java/org/springframework/http/ContentDisposition.java#L259-L267 Symphony https://github.com/symfony/symfony/blob/123b1651c4a7e219ba59074441badfac65525efe/src/Symfony/Component/Mime/Header/ParameterizedHeader.php#L128-L133 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
0.1.8
0.10.0
0.10.1
0.10.2
0.11.0
+ 67 more Show less
0.12.0
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.15.7
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.0
0.17.1
0.17.3
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.7.0
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
Fixed in
0.21.0
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.18.1
patch
2 CVEs
CVE-2025-68696
GHSA-hm5p-x4rq-38w4
Dec 23, 2025
httparty Has Potential SSRF Vulnerability That Leads to API Key Leakage
High
Network
Low
None
None
SummaryThere may be an SSRF vulnerability in httparty. This issue can pose a risk of leaking API keys, and it can also allow third parties to issue requests to internal servers. DetailsWhen httparty receives a path argument that is an absolute URL, it ignores the Consider the following example of a web application:
Now, suppose an attacker sends a request like this:
In this case, httparty sends the A similar problem was reported and fixed in the HTTP client library axios in the past: Also, Python's PoCFollow these steps to reproduce the issue:
Although Impact
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
0.1.8
0.10.0
0.10.1
0.10.2
0.11.0
+ 72 more Show less
0.12.0
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.15.7
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.0
0.17.1
0.17.3
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.7.0
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
Fixed in
0.24.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-22049
GHSA-5pq7-52mg-hr42
Jan 03, 2023
httparty has multipart/form-data request tampering vulnerability
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
ImpactI found "multipart/form-data request tampering vulnerability" caused by Content-Disposition "filename" lack of escaping in httparty.
https://github.com/jnunemaker/httparty/blob/4416141d37fd71bdba4f37589ec265f55aa446ce/lib/httparty/request/body.rb#L43 By exploiting this problem, the following attacks are possible
For example, this vulnerability can be exploited to generate the following Content-Disposition.
The Abused Header has multiple name ( These problems can result in successful or unsuccessful attacks, depending on the behavior of the parser receiving the request. I have confirmed that the attack succeeds, at least in the following frameworks
The cause of this problem is the lack of escaping of the WhatWG's HTML spec has an escaping requirement. https://html.spec.whatwg.org/#multipart-form-data
PatchesAs noted at the beginning of this section, encoding must be done as described in the HTML Spec. https://html.spec.whatwg.org/#multipart-form-data
Therefore, it is recommended that Content-Disposition be modified by either of the following
https://github.com/jnunemaker/httparty/blob/4416141d37fd71bdba4f37589ec265f55aa446ce/lib/httparty/request/body.rb#L43
Also, as for PoCPoC EnvironmentOS: macOS Monterey(12.3) Ruby ver: ruby 3.1.2p20 httparty ver: 0.20.0 (Python3 - HTTP Request Logging Server) PoC procedure(Linux or MacOS is required.
This is because Windows does not allow file names containing
I write Python code, but any method will work as long as you can see the HTTP Request Body. (e.g. Debugger, HTTP Logging Server, Packet Capture) $ vi logging.py
$ python logging.py
Return Request Header & Body:
Content-Disposition:
References
Golang https://github.com/golang/go/blob/e0e0c8fe9881bbbfe689ad94ca5dddbb252e4233/src/mime/multipart/writer.go#L144 Spring https://github.com/spring-projects/spring-framework/blob/4cc91e46b210b4e4e7ed182f93994511391b54ed/spring-web/src/main/java/org/springframework/http/ContentDisposition.java#L259-L267 Symphony https://github.com/symfony/symfony/blob/123b1651c4a7e219ba59074441badfac65525efe/src/Symfony/Component/Mime/Header/ParameterizedHeader.php#L128-L133 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
0.1.8
0.10.0
0.10.1
0.10.2
0.11.0
+ 67 more Show less
0.12.0
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.15.7
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.0
0.17.1
0.17.3
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.7.0
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
Fixed in
0.21.0
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.18.0
minor
2 CVEs
CVE-2025-68696
GHSA-hm5p-x4rq-38w4
Dec 23, 2025
httparty Has Potential SSRF Vulnerability That Leads to API Key Leakage
High
Network
Low
None
None
SummaryThere may be an SSRF vulnerability in httparty. This issue can pose a risk of leaking API keys, and it can also allow third parties to issue requests to internal servers. DetailsWhen httparty receives a path argument that is an absolute URL, it ignores the Consider the following example of a web application:
Now, suppose an attacker sends a request like this:
In this case, httparty sends the A similar problem was reported and fixed in the HTTP client library axios in the past: Also, Python's PoCFollow these steps to reproduce the issue:
Although Impact
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
0.1.8
0.10.0
0.10.1
0.10.2
0.11.0
+ 72 more Show less
0.12.0
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.15.7
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.0
0.17.1
0.17.3
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.7.0
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
Fixed in
0.24.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-22049
GHSA-5pq7-52mg-hr42
Jan 03, 2023
httparty has multipart/form-data request tampering vulnerability
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
ImpactI found "multipart/form-data request tampering vulnerability" caused by Content-Disposition "filename" lack of escaping in httparty.
https://github.com/jnunemaker/httparty/blob/4416141d37fd71bdba4f37589ec265f55aa446ce/lib/httparty/request/body.rb#L43 By exploiting this problem, the following attacks are possible
For example, this vulnerability can be exploited to generate the following Content-Disposition.
The Abused Header has multiple name ( These problems can result in successful or unsuccessful attacks, depending on the behavior of the parser receiving the request. I have confirmed that the attack succeeds, at least in the following frameworks
The cause of this problem is the lack of escaping of the WhatWG's HTML spec has an escaping requirement. https://html.spec.whatwg.org/#multipart-form-data
PatchesAs noted at the beginning of this section, encoding must be done as described in the HTML Spec. https://html.spec.whatwg.org/#multipart-form-data
Therefore, it is recommended that Content-Disposition be modified by either of the following
https://github.com/jnunemaker/httparty/blob/4416141d37fd71bdba4f37589ec265f55aa446ce/lib/httparty/request/body.rb#L43
Also, as for PoCPoC EnvironmentOS: macOS Monterey(12.3) Ruby ver: ruby 3.1.2p20 httparty ver: 0.20.0 (Python3 - HTTP Request Logging Server) PoC procedure(Linux or MacOS is required.
This is because Windows does not allow file names containing
I write Python code, but any method will work as long as you can see the HTTP Request Body. (e.g. Debugger, HTTP Logging Server, Packet Capture) $ vi logging.py
$ python logging.py
Return Request Header & Body:
Content-Disposition:
References
Golang https://github.com/golang/go/blob/e0e0c8fe9881bbbfe689ad94ca5dddbb252e4233/src/mime/multipart/writer.go#L144 Spring https://github.com/spring-projects/spring-framework/blob/4cc91e46b210b4e4e7ed182f93994511391b54ed/spring-web/src/main/java/org/springframework/http/ContentDisposition.java#L259-L267 Symphony https://github.com/symfony/symfony/blob/123b1651c4a7e219ba59074441badfac65525efe/src/Symfony/Component/Mime/Header/ParameterizedHeader.php#L128-L133 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
0.1.8
0.10.0
0.10.1
0.10.2
0.11.0
+ 67 more Show less
0.12.0
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.15.7
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.0
0.17.1
0.17.3
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.7.0
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
Fixed in
0.21.0
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.17.3
patch
2 CVEs
CVE-2025-68696
GHSA-hm5p-x4rq-38w4
Dec 23, 2025
httparty Has Potential SSRF Vulnerability That Leads to API Key Leakage
High
Network
Low
None
None
SummaryThere may be an SSRF vulnerability in httparty. This issue can pose a risk of leaking API keys, and it can also allow third parties to issue requests to internal servers. DetailsWhen httparty receives a path argument that is an absolute URL, it ignores the Consider the following example of a web application:
Now, suppose an attacker sends a request like this:
In this case, httparty sends the A similar problem was reported and fixed in the HTTP client library axios in the past: Also, Python's PoCFollow these steps to reproduce the issue:
Although Impact
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
0.1.8
0.10.0
0.10.1
0.10.2
0.11.0
+ 72 more Show less
0.12.0
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.15.7
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.0
0.17.1
0.17.3
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.7.0
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
Fixed in
0.24.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-22049
GHSA-5pq7-52mg-hr42
Jan 03, 2023
httparty has multipart/form-data request tampering vulnerability
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
ImpactI found "multipart/form-data request tampering vulnerability" caused by Content-Disposition "filename" lack of escaping in httparty.
https://github.com/jnunemaker/httparty/blob/4416141d37fd71bdba4f37589ec265f55aa446ce/lib/httparty/request/body.rb#L43 By exploiting this problem, the following attacks are possible
For example, this vulnerability can be exploited to generate the following Content-Disposition.
The Abused Header has multiple name ( These problems can result in successful or unsuccessful attacks, depending on the behavior of the parser receiving the request. I have confirmed that the attack succeeds, at least in the following frameworks
The cause of this problem is the lack of escaping of the WhatWG's HTML spec has an escaping requirement. https://html.spec.whatwg.org/#multipart-form-data
PatchesAs noted at the beginning of this section, encoding must be done as described in the HTML Spec. https://html.spec.whatwg.org/#multipart-form-data
Therefore, it is recommended that Content-Disposition be modified by either of the following
https://github.com/jnunemaker/httparty/blob/4416141d37fd71bdba4f37589ec265f55aa446ce/lib/httparty/request/body.rb#L43
Also, as for PoCPoC EnvironmentOS: macOS Monterey(12.3) Ruby ver: ruby 3.1.2p20 httparty ver: 0.20.0 (Python3 - HTTP Request Logging Server) PoC procedure(Linux or MacOS is required.
This is because Windows does not allow file names containing
I write Python code, but any method will work as long as you can see the HTTP Request Body. (e.g. Debugger, HTTP Logging Server, Packet Capture) $ vi logging.py
$ python logging.py
Return Request Header & Body:
Content-Disposition:
References
Golang https://github.com/golang/go/blob/e0e0c8fe9881bbbfe689ad94ca5dddbb252e4233/src/mime/multipart/writer.go#L144 Spring https://github.com/spring-projects/spring-framework/blob/4cc91e46b210b4e4e7ed182f93994511391b54ed/spring-web/src/main/java/org/springframework/http/ContentDisposition.java#L259-L267 Symphony https://github.com/symfony/symfony/blob/123b1651c4a7e219ba59074441badfac65525efe/src/Symfony/Component/Mime/Header/ParameterizedHeader.php#L128-L133 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
0.1.8
0.10.0
0.10.1
0.10.2
0.11.0
+ 67 more Show less
0.12.0
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.15.7
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.0
0.17.1
0.17.3
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.7.0
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
Fixed in
0.21.0
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.17.1
patch
2 CVEs
CVE-2025-68696
GHSA-hm5p-x4rq-38w4
Dec 23, 2025
httparty Has Potential SSRF Vulnerability That Leads to API Key Leakage
High
Network
Low
None
None
SummaryThere may be an SSRF vulnerability in httparty. This issue can pose a risk of leaking API keys, and it can also allow third parties to issue requests to internal servers. DetailsWhen httparty receives a path argument that is an absolute URL, it ignores the Consider the following example of a web application:
Now, suppose an attacker sends a request like this:
In this case, httparty sends the A similar problem was reported and fixed in the HTTP client library axios in the past: Also, Python's PoCFollow these steps to reproduce the issue:
Although Impact
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
0.1.8
0.10.0
0.10.1
0.10.2
0.11.0
+ 72 more Show less
0.12.0
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.15.7
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.0
0.17.1
0.17.3
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.7.0
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
Fixed in
0.24.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-22049
GHSA-5pq7-52mg-hr42
Jan 03, 2023
httparty has multipart/form-data request tampering vulnerability
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
ImpactI found "multipart/form-data request tampering vulnerability" caused by Content-Disposition "filename" lack of escaping in httparty.
https://github.com/jnunemaker/httparty/blob/4416141d37fd71bdba4f37589ec265f55aa446ce/lib/httparty/request/body.rb#L43 By exploiting this problem, the following attacks are possible
For example, this vulnerability can be exploited to generate the following Content-Disposition.
The Abused Header has multiple name ( These problems can result in successful or unsuccessful attacks, depending on the behavior of the parser receiving the request. I have confirmed that the attack succeeds, at least in the following frameworks
The cause of this problem is the lack of escaping of the WhatWG's HTML spec has an escaping requirement. https://html.spec.whatwg.org/#multipart-form-data
PatchesAs noted at the beginning of this section, encoding must be done as described in the HTML Spec. https://html.spec.whatwg.org/#multipart-form-data
Therefore, it is recommended that Content-Disposition be modified by either of the following
https://github.com/jnunemaker/httparty/blob/4416141d37fd71bdba4f37589ec265f55aa446ce/lib/httparty/request/body.rb#L43
Also, as for PoCPoC EnvironmentOS: macOS Monterey(12.3) Ruby ver: ruby 3.1.2p20 httparty ver: 0.20.0 (Python3 - HTTP Request Logging Server) PoC procedure(Linux or MacOS is required.
This is because Windows does not allow file names containing
I write Python code, but any method will work as long as you can see the HTTP Request Body. (e.g. Debugger, HTTP Logging Server, Packet Capture) $ vi logging.py
$ python logging.py
Return Request Header & Body:
Content-Disposition:
References
Golang https://github.com/golang/go/blob/e0e0c8fe9881bbbfe689ad94ca5dddbb252e4233/src/mime/multipart/writer.go#L144 Spring https://github.com/spring-projects/spring-framework/blob/4cc91e46b210b4e4e7ed182f93994511391b54ed/spring-web/src/main/java/org/springframework/http/ContentDisposition.java#L259-L267 Symphony https://github.com/symfony/symfony/blob/123b1651c4a7e219ba59074441badfac65525efe/src/Symfony/Component/Mime/Header/ParameterizedHeader.php#L128-L133 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
0.1.8
0.10.0
0.10.1
0.10.2
0.11.0
+ 67 more Show less
0.12.0
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.15.7
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.0
0.17.1
0.17.3
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.7.0
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
Fixed in
0.21.0
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.17.0
minor
2 CVEs
CVE-2025-68696
GHSA-hm5p-x4rq-38w4
Dec 23, 2025
httparty Has Potential SSRF Vulnerability That Leads to API Key Leakage
High
Network
Low
None
None
SummaryThere may be an SSRF vulnerability in httparty. This issue can pose a risk of leaking API keys, and it can also allow third parties to issue requests to internal servers. DetailsWhen httparty receives a path argument that is an absolute URL, it ignores the Consider the following example of a web application:
Now, suppose an attacker sends a request like this:
In this case, httparty sends the A similar problem was reported and fixed in the HTTP client library axios in the past: Also, Python's PoCFollow these steps to reproduce the issue:
Although Impact
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
0.1.8
0.10.0
0.10.1
0.10.2
0.11.0
+ 72 more Show less
0.12.0
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.15.7
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.0
0.17.1
0.17.3
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.7.0
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
Fixed in
0.24.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-22049
GHSA-5pq7-52mg-hr42
Jan 03, 2023
httparty has multipart/form-data request tampering vulnerability
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
ImpactI found "multipart/form-data request tampering vulnerability" caused by Content-Disposition "filename" lack of escaping in httparty.
https://github.com/jnunemaker/httparty/blob/4416141d37fd71bdba4f37589ec265f55aa446ce/lib/httparty/request/body.rb#L43 By exploiting this problem, the following attacks are possible
For example, this vulnerability can be exploited to generate the following Content-Disposition.
The Abused Header has multiple name ( These problems can result in successful or unsuccessful attacks, depending on the behavior of the parser receiving the request. I have confirmed that the attack succeeds, at least in the following frameworks
The cause of this problem is the lack of escaping of the WhatWG's HTML spec has an escaping requirement. https://html.spec.whatwg.org/#multipart-form-data
PatchesAs noted at the beginning of this section, encoding must be done as described in the HTML Spec. https://html.spec.whatwg.org/#multipart-form-data
Therefore, it is recommended that Content-Disposition be modified by either of the following
https://github.com/jnunemaker/httparty/blob/4416141d37fd71bdba4f37589ec265f55aa446ce/lib/httparty/request/body.rb#L43
Also, as for PoCPoC EnvironmentOS: macOS Monterey(12.3) Ruby ver: ruby 3.1.2p20 httparty ver: 0.20.0 (Python3 - HTTP Request Logging Server) PoC procedure(Linux or MacOS is required.
This is because Windows does not allow file names containing
I write Python code, but any method will work as long as you can see the HTTP Request Body. (e.g. Debugger, HTTP Logging Server, Packet Capture) $ vi logging.py
$ python logging.py
Return Request Header & Body:
Content-Disposition:
References
Golang https://github.com/golang/go/blob/e0e0c8fe9881bbbfe689ad94ca5dddbb252e4233/src/mime/multipart/writer.go#L144 Spring https://github.com/spring-projects/spring-framework/blob/4cc91e46b210b4e4e7ed182f93994511391b54ed/spring-web/src/main/java/org/springframework/http/ContentDisposition.java#L259-L267 Symphony https://github.com/symfony/symfony/blob/123b1651c4a7e219ba59074441badfac65525efe/src/Symfony/Component/Mime/Header/ParameterizedHeader.php#L128-L133 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
0.1.8
0.10.0
0.10.1
0.10.2
0.11.0
+ 67 more Show less
0.12.0
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.15.7
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.0
0.17.1
0.17.3
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.7.0
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
Fixed in
0.21.0
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.16.4
patch
2 CVEs
CVE-2025-68696
GHSA-hm5p-x4rq-38w4
Dec 23, 2025
httparty Has Potential SSRF Vulnerability That Leads to API Key Leakage
High
Network
Low
None
None
SummaryThere may be an SSRF vulnerability in httparty. This issue can pose a risk of leaking API keys, and it can also allow third parties to issue requests to internal servers. DetailsWhen httparty receives a path argument that is an absolute URL, it ignores the Consider the following example of a web application:
Now, suppose an attacker sends a request like this:
In this case, httparty sends the A similar problem was reported and fixed in the HTTP client library axios in the past: Also, Python's PoCFollow these steps to reproduce the issue:
Although Impact
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
0.1.8
0.10.0
0.10.1
0.10.2
0.11.0
+ 72 more Show less
0.12.0
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.15.7
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.0
0.17.1
0.17.3
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.7.0
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
Fixed in
0.24.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-22049
GHSA-5pq7-52mg-hr42
Jan 03, 2023
httparty has multipart/form-data request tampering vulnerability
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
ImpactI found "multipart/form-data request tampering vulnerability" caused by Content-Disposition "filename" lack of escaping in httparty.
https://github.com/jnunemaker/httparty/blob/4416141d37fd71bdba4f37589ec265f55aa446ce/lib/httparty/request/body.rb#L43 By exploiting this problem, the following attacks are possible
For example, this vulnerability can be exploited to generate the following Content-Disposition.
The Abused Header has multiple name ( These problems can result in successful or unsuccessful attacks, depending on the behavior of the parser receiving the request. I have confirmed that the attack succeeds, at least in the following frameworks
The cause of this problem is the lack of escaping of the WhatWG's HTML spec has an escaping requirement. https://html.spec.whatwg.org/#multipart-form-data
PatchesAs noted at the beginning of this section, encoding must be done as described in the HTML Spec. https://html.spec.whatwg.org/#multipart-form-data
Therefore, it is recommended that Content-Disposition be modified by either of the following
https://github.com/jnunemaker/httparty/blob/4416141d37fd71bdba4f37589ec265f55aa446ce/lib/httparty/request/body.rb#L43
Also, as for PoCPoC EnvironmentOS: macOS Monterey(12.3) Ruby ver: ruby 3.1.2p20 httparty ver: 0.20.0 (Python3 - HTTP Request Logging Server) PoC procedure(Linux or MacOS is required.
This is because Windows does not allow file names containing
I write Python code, but any method will work as long as you can see the HTTP Request Body. (e.g. Debugger, HTTP Logging Server, Packet Capture) $ vi logging.py
$ python logging.py
Return Request Header & Body:
Content-Disposition:
References
Golang https://github.com/golang/go/blob/e0e0c8fe9881bbbfe689ad94ca5dddbb252e4233/src/mime/multipart/writer.go#L144 Spring https://github.com/spring-projects/spring-framework/blob/4cc91e46b210b4e4e7ed182f93994511391b54ed/spring-web/src/main/java/org/springframework/http/ContentDisposition.java#L259-L267 Symphony https://github.com/symfony/symfony/blob/123b1651c4a7e219ba59074441badfac65525efe/src/Symfony/Component/Mime/Header/ParameterizedHeader.php#L128-L133 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
0.1.8
0.10.0
0.10.1
0.10.2
0.11.0
+ 67 more Show less
0.12.0
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.15.7
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.0
0.17.1
0.17.3
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.7.0
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
Fixed in
0.21.0
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.16.3
patch
2 CVEs
CVE-2025-68696
GHSA-hm5p-x4rq-38w4
Dec 23, 2025
httparty Has Potential SSRF Vulnerability That Leads to API Key Leakage
High
Network
Low
None
None
SummaryThere may be an SSRF vulnerability in httparty. This issue can pose a risk of leaking API keys, and it can also allow third parties to issue requests to internal servers. DetailsWhen httparty receives a path argument that is an absolute URL, it ignores the Consider the following example of a web application:
Now, suppose an attacker sends a request like this:
In this case, httparty sends the A similar problem was reported and fixed in the HTTP client library axios in the past: Also, Python's PoCFollow these steps to reproduce the issue:
Although Impact
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
0.1.8
0.10.0
0.10.1
0.10.2
0.11.0
+ 72 more Show less
0.12.0
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.15.7
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.0
0.17.1
0.17.3
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.7.0
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
Fixed in
0.24.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-22049
GHSA-5pq7-52mg-hr42
Jan 03, 2023
httparty has multipart/form-data request tampering vulnerability
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
ImpactI found "multipart/form-data request tampering vulnerability" caused by Content-Disposition "filename" lack of escaping in httparty.
https://github.com/jnunemaker/httparty/blob/4416141d37fd71bdba4f37589ec265f55aa446ce/lib/httparty/request/body.rb#L43 By exploiting this problem, the following attacks are possible
For example, this vulnerability can be exploited to generate the following Content-Disposition.
The Abused Header has multiple name ( These problems can result in successful or unsuccessful attacks, depending on the behavior of the parser receiving the request. I have confirmed that the attack succeeds, at least in the following frameworks
The cause of this problem is the lack of escaping of the WhatWG's HTML spec has an escaping requirement. https://html.spec.whatwg.org/#multipart-form-data
PatchesAs noted at the beginning of this section, encoding must be done as described in the HTML Spec. https://html.spec.whatwg.org/#multipart-form-data
Therefore, it is recommended that Content-Disposition be modified by either of the following
https://github.com/jnunemaker/httparty/blob/4416141d37fd71bdba4f37589ec265f55aa446ce/lib/httparty/request/body.rb#L43
Also, as for PoCPoC EnvironmentOS: macOS Monterey(12.3) Ruby ver: ruby 3.1.2p20 httparty ver: 0.20.0 (Python3 - HTTP Request Logging Server) PoC procedure(Linux or MacOS is required.
This is because Windows does not allow file names containing
I write Python code, but any method will work as long as you can see the HTTP Request Body. (e.g. Debugger, HTTP Logging Server, Packet Capture) $ vi logging.py
$ python logging.py
Return Request Header & Body:
Content-Disposition:
References
Golang https://github.com/golang/go/blob/e0e0c8fe9881bbbfe689ad94ca5dddbb252e4233/src/mime/multipart/writer.go#L144 Spring https://github.com/spring-projects/spring-framework/blob/4cc91e46b210b4e4e7ed182f93994511391b54ed/spring-web/src/main/java/org/springframework/http/ContentDisposition.java#L259-L267 Symphony https://github.com/symfony/symfony/blob/123b1651c4a7e219ba59074441badfac65525efe/src/Symfony/Component/Mime/Header/ParameterizedHeader.php#L128-L133 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
0.1.8
0.10.0
0.10.1
0.10.2
0.11.0
+ 67 more Show less
0.12.0
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.15.7
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.0
0.17.1
0.17.3
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.7.0
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
Fixed in
0.21.0
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.16.2
patch
2 CVEs
CVE-2025-68696
GHSA-hm5p-x4rq-38w4
Dec 23, 2025
httparty Has Potential SSRF Vulnerability That Leads to API Key Leakage
High
Network
Low
None
None
SummaryThere may be an SSRF vulnerability in httparty. This issue can pose a risk of leaking API keys, and it can also allow third parties to issue requests to internal servers. DetailsWhen httparty receives a path argument that is an absolute URL, it ignores the Consider the following example of a web application:
Now, suppose an attacker sends a request like this:
In this case, httparty sends the A similar problem was reported and fixed in the HTTP client library axios in the past: Also, Python's PoCFollow these steps to reproduce the issue:
Although Impact
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
0.1.8
0.10.0
0.10.1
0.10.2
0.11.0
+ 72 more Show less
0.12.0
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.15.7
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.0
0.17.1
0.17.3
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.7.0
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
Fixed in
0.24.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-22049
GHSA-5pq7-52mg-hr42
Jan 03, 2023
httparty has multipart/form-data request tampering vulnerability
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
ImpactI found "multipart/form-data request tampering vulnerability" caused by Content-Disposition "filename" lack of escaping in httparty.
https://github.com/jnunemaker/httparty/blob/4416141d37fd71bdba4f37589ec265f55aa446ce/lib/httparty/request/body.rb#L43 By exploiting this problem, the following attacks are possible
For example, this vulnerability can be exploited to generate the following Content-Disposition.
The Abused Header has multiple name ( These problems can result in successful or unsuccessful attacks, depending on the behavior of the parser receiving the request. I have confirmed that the attack succeeds, at least in the following frameworks
The cause of this problem is the lack of escaping of the WhatWG's HTML spec has an escaping requirement. https://html.spec.whatwg.org/#multipart-form-data
PatchesAs noted at the beginning of this section, encoding must be done as described in the HTML Spec. https://html.spec.whatwg.org/#multipart-form-data
Therefore, it is recommended that Content-Disposition be modified by either of the following
https://github.com/jnunemaker/httparty/blob/4416141d37fd71bdba4f37589ec265f55aa446ce/lib/httparty/request/body.rb#L43
Also, as for PoCPoC EnvironmentOS: macOS Monterey(12.3) Ruby ver: ruby 3.1.2p20 httparty ver: 0.20.0 (Python3 - HTTP Request Logging Server) PoC procedure(Linux or MacOS is required.
This is because Windows does not allow file names containing
I write Python code, but any method will work as long as you can see the HTTP Request Body. (e.g. Debugger, HTTP Logging Server, Packet Capture) $ vi logging.py
$ python logging.py
Return Request Header & Body:
Content-Disposition:
References
Golang https://github.com/golang/go/blob/e0e0c8fe9881bbbfe689ad94ca5dddbb252e4233/src/mime/multipart/writer.go#L144 Spring https://github.com/spring-projects/spring-framework/blob/4cc91e46b210b4e4e7ed182f93994511391b54ed/spring-web/src/main/java/org/springframework/http/ContentDisposition.java#L259-L267 Symphony https://github.com/symfony/symfony/blob/123b1651c4a7e219ba59074441badfac65525efe/src/Symfony/Component/Mime/Header/ParameterizedHeader.php#L128-L133 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
0.1.8
0.10.0
0.10.1
0.10.2
0.11.0
+ 67 more Show less
0.12.0
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.15.7
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.0
0.17.1
0.17.3
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.7.0
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
Fixed in
0.21.0
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.16.1
patch
2 CVEs
CVE-2025-68696
GHSA-hm5p-x4rq-38w4
Dec 23, 2025
httparty Has Potential SSRF Vulnerability That Leads to API Key Leakage
High
Network
Low
None
None
SummaryThere may be an SSRF vulnerability in httparty. This issue can pose a risk of leaking API keys, and it can also allow third parties to issue requests to internal servers. DetailsWhen httparty receives a path argument that is an absolute URL, it ignores the Consider the following example of a web application:
Now, suppose an attacker sends a request like this:
In this case, httparty sends the A similar problem was reported and fixed in the HTTP client library axios in the past: Also, Python's PoCFollow these steps to reproduce the issue:
Although Impact
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
0.1.8
0.10.0
0.10.1
0.10.2
0.11.0
+ 72 more Show less
0.12.0
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.15.7
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.0
0.17.1
0.17.3
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.7.0
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
Fixed in
0.24.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-22049
GHSA-5pq7-52mg-hr42
Jan 03, 2023
httparty has multipart/form-data request tampering vulnerability
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
ImpactI found "multipart/form-data request tampering vulnerability" caused by Content-Disposition "filename" lack of escaping in httparty.
https://github.com/jnunemaker/httparty/blob/4416141d37fd71bdba4f37589ec265f55aa446ce/lib/httparty/request/body.rb#L43 By exploiting this problem, the following attacks are possible
For example, this vulnerability can be exploited to generate the following Content-Disposition.
The Abused Header has multiple name ( These problems can result in successful or unsuccessful attacks, depending on the behavior of the parser receiving the request. I have confirmed that the attack succeeds, at least in the following frameworks
The cause of this problem is the lack of escaping of the WhatWG's HTML spec has an escaping requirement. https://html.spec.whatwg.org/#multipart-form-data
PatchesAs noted at the beginning of this section, encoding must be done as described in the HTML Spec. https://html.spec.whatwg.org/#multipart-form-data
Therefore, it is recommended that Content-Disposition be modified by either of the following
https://github.com/jnunemaker/httparty/blob/4416141d37fd71bdba4f37589ec265f55aa446ce/lib/httparty/request/body.rb#L43
Also, as for PoCPoC EnvironmentOS: macOS Monterey(12.3) Ruby ver: ruby 3.1.2p20 httparty ver: 0.20.0 (Python3 - HTTP Request Logging Server) PoC procedure(Linux or MacOS is required.
This is because Windows does not allow file names containing
I write Python code, but any method will work as long as you can see the HTTP Request Body. (e.g. Debugger, HTTP Logging Server, Packet Capture) $ vi logging.py
$ python logging.py
Return Request Header & Body:
Content-Disposition:
References
Golang https://github.com/golang/go/blob/e0e0c8fe9881bbbfe689ad94ca5dddbb252e4233/src/mime/multipart/writer.go#L144 Spring https://github.com/spring-projects/spring-framework/blob/4cc91e46b210b4e4e7ed182f93994511391b54ed/spring-web/src/main/java/org/springframework/http/ContentDisposition.java#L259-L267 Symphony https://github.com/symfony/symfony/blob/123b1651c4a7e219ba59074441badfac65525efe/src/Symfony/Component/Mime/Header/ParameterizedHeader.php#L128-L133 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
0.1.8
0.10.0
0.10.1
0.10.2
0.11.0
+ 67 more Show less
0.12.0
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.15.7
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.0
0.17.1
0.17.3
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.7.0
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
Fixed in
0.21.0
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.16.0
minor
2 CVEs
CVE-2025-68696
GHSA-hm5p-x4rq-38w4
Dec 23, 2025
httparty Has Potential SSRF Vulnerability That Leads to API Key Leakage
High
Network
Low
None
None
SummaryThere may be an SSRF vulnerability in httparty. This issue can pose a risk of leaking API keys, and it can also allow third parties to issue requests to internal servers. DetailsWhen httparty receives a path argument that is an absolute URL, it ignores the Consider the following example of a web application:
Now, suppose an attacker sends a request like this:
In this case, httparty sends the A similar problem was reported and fixed in the HTTP client library axios in the past: Also, Python's PoCFollow these steps to reproduce the issue:
Although Impact
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
0.1.8
0.10.0
0.10.1
0.10.2
0.11.0
+ 72 more Show less
0.12.0
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.15.7
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.0
0.17.1
0.17.3
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.7.0
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
Fixed in
0.24.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-22049
GHSA-5pq7-52mg-hr42
Jan 03, 2023
httparty has multipart/form-data request tampering vulnerability
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
ImpactI found "multipart/form-data request tampering vulnerability" caused by Content-Disposition "filename" lack of escaping in httparty.
https://github.com/jnunemaker/httparty/blob/4416141d37fd71bdba4f37589ec265f55aa446ce/lib/httparty/request/body.rb#L43 By exploiting this problem, the following attacks are possible
For example, this vulnerability can be exploited to generate the following Content-Disposition.
The Abused Header has multiple name ( These problems can result in successful or unsuccessful attacks, depending on the behavior of the parser receiving the request. I have confirmed that the attack succeeds, at least in the following frameworks
The cause of this problem is the lack of escaping of the WhatWG's HTML spec has an escaping requirement. https://html.spec.whatwg.org/#multipart-form-data
PatchesAs noted at the beginning of this section, encoding must be done as described in the HTML Spec. https://html.spec.whatwg.org/#multipart-form-data
Therefore, it is recommended that Content-Disposition be modified by either of the following
https://github.com/jnunemaker/httparty/blob/4416141d37fd71bdba4f37589ec265f55aa446ce/lib/httparty/request/body.rb#L43
Also, as for PoCPoC EnvironmentOS: macOS Monterey(12.3) Ruby ver: ruby 3.1.2p20 httparty ver: 0.20.0 (Python3 - HTTP Request Logging Server) PoC procedure(Linux or MacOS is required.
This is because Windows does not allow file names containing
I write Python code, but any method will work as long as you can see the HTTP Request Body. (e.g. Debugger, HTTP Logging Server, Packet Capture) $ vi logging.py
$ python logging.py
Return Request Header & Body:
Content-Disposition:
References
Golang https://github.com/golang/go/blob/e0e0c8fe9881bbbfe689ad94ca5dddbb252e4233/src/mime/multipart/writer.go#L144 Spring https://github.com/spring-projects/spring-framework/blob/4cc91e46b210b4e4e7ed182f93994511391b54ed/spring-web/src/main/java/org/springframework/http/ContentDisposition.java#L259-L267 Symphony https://github.com/symfony/symfony/blob/123b1651c4a7e219ba59074441badfac65525efe/src/Symfony/Component/Mime/Header/ParameterizedHeader.php#L128-L133 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
0.1.8
0.10.0
0.10.1
0.10.2
0.11.0
+ 67 more Show less
0.12.0
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.15.7
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.0
0.17.1
0.17.3
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.7.0
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
Fixed in
0.21.0
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.15.7
patch
2 CVEs
CVE-2025-68696
GHSA-hm5p-x4rq-38w4
Dec 23, 2025
httparty Has Potential SSRF Vulnerability That Leads to API Key Leakage
High
Network
Low
None
None
SummaryThere may be an SSRF vulnerability in httparty. This issue can pose a risk of leaking API keys, and it can also allow third parties to issue requests to internal servers. DetailsWhen httparty receives a path argument that is an absolute URL, it ignores the Consider the following example of a web application:
Now, suppose an attacker sends a request like this:
In this case, httparty sends the A similar problem was reported and fixed in the HTTP client library axios in the past: Also, Python's PoCFollow these steps to reproduce the issue:
Although Impact
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
0.1.8
0.10.0
0.10.1
0.10.2
0.11.0
+ 72 more Show less
0.12.0
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.15.7
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.0
0.17.1
0.17.3
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.7.0
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
Fixed in
0.24.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-22049
GHSA-5pq7-52mg-hr42
Jan 03, 2023
httparty has multipart/form-data request tampering vulnerability
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
ImpactI found "multipart/form-data request tampering vulnerability" caused by Content-Disposition "filename" lack of escaping in httparty.
https://github.com/jnunemaker/httparty/blob/4416141d37fd71bdba4f37589ec265f55aa446ce/lib/httparty/request/body.rb#L43 By exploiting this problem, the following attacks are possible
For example, this vulnerability can be exploited to generate the following Content-Disposition.
The Abused Header has multiple name ( These problems can result in successful or unsuccessful attacks, depending on the behavior of the parser receiving the request. I have confirmed that the attack succeeds, at least in the following frameworks
The cause of this problem is the lack of escaping of the WhatWG's HTML spec has an escaping requirement. https://html.spec.whatwg.org/#multipart-form-data
PatchesAs noted at the beginning of this section, encoding must be done as described in the HTML Spec. https://html.spec.whatwg.org/#multipart-form-data
Therefore, it is recommended that Content-Disposition be modified by either of the following
https://github.com/jnunemaker/httparty/blob/4416141d37fd71bdba4f37589ec265f55aa446ce/lib/httparty/request/body.rb#L43
Also, as for PoCPoC EnvironmentOS: macOS Monterey(12.3) Ruby ver: ruby 3.1.2p20 httparty ver: 0.20.0 (Python3 - HTTP Request Logging Server) PoC procedure(Linux or MacOS is required.
This is because Windows does not allow file names containing
I write Python code, but any method will work as long as you can see the HTTP Request Body. (e.g. Debugger, HTTP Logging Server, Packet Capture) $ vi logging.py
$ python logging.py
Return Request Header & Body:
Content-Disposition:
References
Golang https://github.com/golang/go/blob/e0e0c8fe9881bbbfe689ad94ca5dddbb252e4233/src/mime/multipart/writer.go#L144 Spring https://github.com/spring-projects/spring-framework/blob/4cc91e46b210b4e4e7ed182f93994511391b54ed/spring-web/src/main/java/org/springframework/http/ContentDisposition.java#L259-L267 Symphony https://github.com/symfony/symfony/blob/123b1651c4a7e219ba59074441badfac65525efe/src/Symfony/Component/Mime/Header/ParameterizedHeader.php#L128-L133 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
0.1.8
0.10.0
0.10.1
0.10.2
0.11.0
+ 67 more Show less
0.12.0
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.15.7
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.0
0.17.1
0.17.3
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.7.0
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
Fixed in
0.21.0
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.15.6
patch
2 CVEs
CVE-2025-68696
GHSA-hm5p-x4rq-38w4
Dec 23, 2025
httparty Has Potential SSRF Vulnerability That Leads to API Key Leakage
High
Network
Low
None
None
SummaryThere may be an SSRF vulnerability in httparty. This issue can pose a risk of leaking API keys, and it can also allow third parties to issue requests to internal servers. DetailsWhen httparty receives a path argument that is an absolute URL, it ignores the Consider the following example of a web application:
Now, suppose an attacker sends a request like this:
In this case, httparty sends the A similar problem was reported and fixed in the HTTP client library axios in the past: Also, Python's PoCFollow these steps to reproduce the issue:
Although Impact
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
0.1.8
0.10.0
0.10.1
0.10.2
0.11.0
+ 72 more Show less
0.12.0
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.15.7
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.0
0.17.1
0.17.3
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.7.0
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
Fixed in
0.24.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-22049
GHSA-5pq7-52mg-hr42
Jan 03, 2023
httparty has multipart/form-data request tampering vulnerability
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
ImpactI found "multipart/form-data request tampering vulnerability" caused by Content-Disposition "filename" lack of escaping in httparty.
https://github.com/jnunemaker/httparty/blob/4416141d37fd71bdba4f37589ec265f55aa446ce/lib/httparty/request/body.rb#L43 By exploiting this problem, the following attacks are possible
For example, this vulnerability can be exploited to generate the following Content-Disposition.
The Abused Header has multiple name ( These problems can result in successful or unsuccessful attacks, depending on the behavior of the parser receiving the request. I have confirmed that the attack succeeds, at least in the following frameworks
The cause of this problem is the lack of escaping of the WhatWG's HTML spec has an escaping requirement. https://html.spec.whatwg.org/#multipart-form-data
PatchesAs noted at the beginning of this section, encoding must be done as described in the HTML Spec. https://html.spec.whatwg.org/#multipart-form-data
Therefore, it is recommended that Content-Disposition be modified by either of the following
https://github.com/jnunemaker/httparty/blob/4416141d37fd71bdba4f37589ec265f55aa446ce/lib/httparty/request/body.rb#L43
Also, as for PoCPoC EnvironmentOS: macOS Monterey(12.3) Ruby ver: ruby 3.1.2p20 httparty ver: 0.20.0 (Python3 - HTTP Request Logging Server) PoC procedure(Linux or MacOS is required.
This is because Windows does not allow file names containing
I write Python code, but any method will work as long as you can see the HTTP Request Body. (e.g. Debugger, HTTP Logging Server, Packet Capture) $ vi logging.py
$ python logging.py
Return Request Header & Body:
Content-Disposition:
References
Golang https://github.com/golang/go/blob/e0e0c8fe9881bbbfe689ad94ca5dddbb252e4233/src/mime/multipart/writer.go#L144 Spring https://github.com/spring-projects/spring-framework/blob/4cc91e46b210b4e4e7ed182f93994511391b54ed/spring-web/src/main/java/org/springframework/http/ContentDisposition.java#L259-L267 Symphony https://github.com/symfony/symfony/blob/123b1651c4a7e219ba59074441badfac65525efe/src/Symfony/Component/Mime/Header/ParameterizedHeader.php#L128-L133 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
0.1.8
0.10.0
0.10.1
0.10.2
0.11.0
+ 67 more Show less
0.12.0
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.15.7
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.0
0.17.1
0.17.3
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.7.0
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
Fixed in
0.21.0
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.15.5
patch
2 CVEs
CVE-2025-68696
GHSA-hm5p-x4rq-38w4
Dec 23, 2025
httparty Has Potential SSRF Vulnerability That Leads to API Key Leakage
High
Network
Low
None
None
SummaryThere may be an SSRF vulnerability in httparty. This issue can pose a risk of leaking API keys, and it can also allow third parties to issue requests to internal servers. DetailsWhen httparty receives a path argument that is an absolute URL, it ignores the Consider the following example of a web application:
Now, suppose an attacker sends a request like this:
In this case, httparty sends the A similar problem was reported and fixed in the HTTP client library axios in the past: Also, Python's PoCFollow these steps to reproduce the issue:
Although Impact
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
0.1.8
0.10.0
0.10.1
0.10.2
0.11.0
+ 72 more Show less
0.12.0
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.15.7
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.0
0.17.1
0.17.3
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.7.0
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
Fixed in
0.24.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-22049
GHSA-5pq7-52mg-hr42
Jan 03, 2023
httparty has multipart/form-data request tampering vulnerability
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
ImpactI found "multipart/form-data request tampering vulnerability" caused by Content-Disposition "filename" lack of escaping in httparty.
https://github.com/jnunemaker/httparty/blob/4416141d37fd71bdba4f37589ec265f55aa446ce/lib/httparty/request/body.rb#L43 By exploiting this problem, the following attacks are possible
For example, this vulnerability can be exploited to generate the following Content-Disposition.
The Abused Header has multiple name ( These problems can result in successful or unsuccessful attacks, depending on the behavior of the parser receiving the request. I have confirmed that the attack succeeds, at least in the following frameworks
The cause of this problem is the lack of escaping of the WhatWG's HTML spec has an escaping requirement. https://html.spec.whatwg.org/#multipart-form-data
PatchesAs noted at the beginning of this section, encoding must be done as described in the HTML Spec. https://html.spec.whatwg.org/#multipart-form-data
Therefore, it is recommended that Content-Disposition be modified by either of the following
https://github.com/jnunemaker/httparty/blob/4416141d37fd71bdba4f37589ec265f55aa446ce/lib/httparty/request/body.rb#L43
Also, as for PoCPoC EnvironmentOS: macOS Monterey(12.3) Ruby ver: ruby 3.1.2p20 httparty ver: 0.20.0 (Python3 - HTTP Request Logging Server) PoC procedure(Linux or MacOS is required.
This is because Windows does not allow file names containing
I write Python code, but any method will work as long as you can see the HTTP Request Body. (e.g. Debugger, HTTP Logging Server, Packet Capture) $ vi logging.py
$ python logging.py
Return Request Header & Body:
Content-Disposition:
References
Golang https://github.com/golang/go/blob/e0e0c8fe9881bbbfe689ad94ca5dddbb252e4233/src/mime/multipart/writer.go#L144 Spring https://github.com/spring-projects/spring-framework/blob/4cc91e46b210b4e4e7ed182f93994511391b54ed/spring-web/src/main/java/org/springframework/http/ContentDisposition.java#L259-L267 Symphony https://github.com/symfony/symfony/blob/123b1651c4a7e219ba59074441badfac65525efe/src/Symfony/Component/Mime/Header/ParameterizedHeader.php#L128-L133 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
0.1.8
0.10.0
0.10.1
0.10.2
0.11.0
+ 67 more Show less
0.12.0
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.15.7
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.0
0.17.1
0.17.3
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.7.0
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
Fixed in
0.21.0
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.15.4
patch
2 CVEs
CVE-2025-68696
GHSA-hm5p-x4rq-38w4
Dec 23, 2025
httparty Has Potential SSRF Vulnerability That Leads to API Key Leakage
High
Network
Low
None
None
SummaryThere may be an SSRF vulnerability in httparty. This issue can pose a risk of leaking API keys, and it can also allow third parties to issue requests to internal servers. DetailsWhen httparty receives a path argument that is an absolute URL, it ignores the Consider the following example of a web application:
Now, suppose an attacker sends a request like this:
In this case, httparty sends the A similar problem was reported and fixed in the HTTP client library axios in the past: Also, Python's PoCFollow these steps to reproduce the issue:
Although Impact
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
0.1.8
0.10.0
0.10.1
0.10.2
0.11.0
+ 72 more Show less
0.12.0
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.15.7
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.0
0.17.1
0.17.3
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.7.0
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
Fixed in
0.24.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-22049
GHSA-5pq7-52mg-hr42
Jan 03, 2023
httparty has multipart/form-data request tampering vulnerability
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
ImpactI found "multipart/form-data request tampering vulnerability" caused by Content-Disposition "filename" lack of escaping in httparty.
https://github.com/jnunemaker/httparty/blob/4416141d37fd71bdba4f37589ec265f55aa446ce/lib/httparty/request/body.rb#L43 By exploiting this problem, the following attacks are possible
For example, this vulnerability can be exploited to generate the following Content-Disposition.
The Abused Header has multiple name ( These problems can result in successful or unsuccessful attacks, depending on the behavior of the parser receiving the request. I have confirmed that the attack succeeds, at least in the following frameworks
The cause of this problem is the lack of escaping of the WhatWG's HTML spec has an escaping requirement. https://html.spec.whatwg.org/#multipart-form-data
PatchesAs noted at the beginning of this section, encoding must be done as described in the HTML Spec. https://html.spec.whatwg.org/#multipart-form-data
Therefore, it is recommended that Content-Disposition be modified by either of the following
https://github.com/jnunemaker/httparty/blob/4416141d37fd71bdba4f37589ec265f55aa446ce/lib/httparty/request/body.rb#L43
Also, as for PoCPoC EnvironmentOS: macOS Monterey(12.3) Ruby ver: ruby 3.1.2p20 httparty ver: 0.20.0 (Python3 - HTTP Request Logging Server) PoC procedure(Linux or MacOS is required.
This is because Windows does not allow file names containing
I write Python code, but any method will work as long as you can see the HTTP Request Body. (e.g. Debugger, HTTP Logging Server, Packet Capture) $ vi logging.py
$ python logging.py
Return Request Header & Body:
Content-Disposition:
References
Golang https://github.com/golang/go/blob/e0e0c8fe9881bbbfe689ad94ca5dddbb252e4233/src/mime/multipart/writer.go#L144 Spring https://github.com/spring-projects/spring-framework/blob/4cc91e46b210b4e4e7ed182f93994511391b54ed/spring-web/src/main/java/org/springframework/http/ContentDisposition.java#L259-L267 Symphony https://github.com/symfony/symfony/blob/123b1651c4a7e219ba59074441badfac65525efe/src/Symfony/Component/Mime/Header/ParameterizedHeader.php#L128-L133 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
0.1.8
0.10.0
0.10.1
0.10.2
0.11.0
+ 67 more Show less
0.12.0
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.15.7
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.0
0.17.1
0.17.3
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.7.0
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
Fixed in
0.21.0
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.15.3
patch
2 CVEs
CVE-2025-68696
GHSA-hm5p-x4rq-38w4
Dec 23, 2025
httparty Has Potential SSRF Vulnerability That Leads to API Key Leakage
High
Network
Low
None
None
SummaryThere may be an SSRF vulnerability in httparty. This issue can pose a risk of leaking API keys, and it can also allow third parties to issue requests to internal servers. DetailsWhen httparty receives a path argument that is an absolute URL, it ignores the Consider the following example of a web application:
Now, suppose an attacker sends a request like this:
In this case, httparty sends the A similar problem was reported and fixed in the HTTP client library axios in the past: Also, Python's PoCFollow these steps to reproduce the issue:
Although Impact
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
0.1.8
0.10.0
0.10.1
0.10.2
0.11.0
+ 72 more Show less
0.12.0
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.15.7
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.0
0.17.1
0.17.3
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.7.0
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
Fixed in
0.24.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-22049
GHSA-5pq7-52mg-hr42
Jan 03, 2023
httparty has multipart/form-data request tampering vulnerability
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
ImpactI found "multipart/form-data request tampering vulnerability" caused by Content-Disposition "filename" lack of escaping in httparty.
https://github.com/jnunemaker/httparty/blob/4416141d37fd71bdba4f37589ec265f55aa446ce/lib/httparty/request/body.rb#L43 By exploiting this problem, the following attacks are possible
For example, this vulnerability can be exploited to generate the following Content-Disposition.
The Abused Header has multiple name ( These problems can result in successful or unsuccessful attacks, depending on the behavior of the parser receiving the request. I have confirmed that the attack succeeds, at least in the following frameworks
The cause of this problem is the lack of escaping of the WhatWG's HTML spec has an escaping requirement. https://html.spec.whatwg.org/#multipart-form-data
PatchesAs noted at the beginning of this section, encoding must be done as described in the HTML Spec. https://html.spec.whatwg.org/#multipart-form-data
Therefore, it is recommended that Content-Disposition be modified by either of the following
https://github.com/jnunemaker/httparty/blob/4416141d37fd71bdba4f37589ec265f55aa446ce/lib/httparty/request/body.rb#L43
Also, as for PoCPoC EnvironmentOS: macOS Monterey(12.3) Ruby ver: ruby 3.1.2p20 httparty ver: 0.20.0 (Python3 - HTTP Request Logging Server) PoC procedure(Linux or MacOS is required.
This is because Windows does not allow file names containing
I write Python code, but any method will work as long as you can see the HTTP Request Body. (e.g. Debugger, HTTP Logging Server, Packet Capture) $ vi logging.py
$ python logging.py
Return Request Header & Body:
Content-Disposition:
References
Golang https://github.com/golang/go/blob/e0e0c8fe9881bbbfe689ad94ca5dddbb252e4233/src/mime/multipart/writer.go#L144 Spring https://github.com/spring-projects/spring-framework/blob/4cc91e46b210b4e4e7ed182f93994511391b54ed/spring-web/src/main/java/org/springframework/http/ContentDisposition.java#L259-L267 Symphony https://github.com/symfony/symfony/blob/123b1651c4a7e219ba59074441badfac65525efe/src/Symfony/Component/Mime/Header/ParameterizedHeader.php#L128-L133 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
0.1.8
0.10.0
0.10.1
0.10.2
0.11.0
+ 67 more Show less
0.12.0
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.15.7
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.0
0.17.1
0.17.3
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.7.0
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
Fixed in
0.21.0
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.15.1
patch
2 CVEs
CVE-2025-68696
GHSA-hm5p-x4rq-38w4
Dec 23, 2025
httparty Has Potential SSRF Vulnerability That Leads to API Key Leakage
High
Network
Low
None
None
SummaryThere may be an SSRF vulnerability in httparty. This issue can pose a risk of leaking API keys, and it can also allow third parties to issue requests to internal servers. DetailsWhen httparty receives a path argument that is an absolute URL, it ignores the Consider the following example of a web application:
Now, suppose an attacker sends a request like this:
In this case, httparty sends the A similar problem was reported and fixed in the HTTP client library axios in the past: Also, Python's PoCFollow these steps to reproduce the issue:
Although Impact
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
0.1.8
0.10.0
0.10.1
0.10.2
0.11.0
+ 72 more Show less
0.12.0
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.15.7
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.0
0.17.1
0.17.3
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.7.0
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
Fixed in
0.24.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-22049
GHSA-5pq7-52mg-hr42
Jan 03, 2023
httparty has multipart/form-data request tampering vulnerability
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
ImpactI found "multipart/form-data request tampering vulnerability" caused by Content-Disposition "filename" lack of escaping in httparty.
https://github.com/jnunemaker/httparty/blob/4416141d37fd71bdba4f37589ec265f55aa446ce/lib/httparty/request/body.rb#L43 By exploiting this problem, the following attacks are possible
For example, this vulnerability can be exploited to generate the following Content-Disposition.
The Abused Header has multiple name ( These problems can result in successful or unsuccessful attacks, depending on the behavior of the parser receiving the request. I have confirmed that the attack succeeds, at least in the following frameworks
The cause of this problem is the lack of escaping of the WhatWG's HTML spec has an escaping requirement. https://html.spec.whatwg.org/#multipart-form-data
PatchesAs noted at the beginning of this section, encoding must be done as described in the HTML Spec. https://html.spec.whatwg.org/#multipart-form-data
Therefore, it is recommended that Content-Disposition be modified by either of the following
https://github.com/jnunemaker/httparty/blob/4416141d37fd71bdba4f37589ec265f55aa446ce/lib/httparty/request/body.rb#L43
Also, as for PoCPoC EnvironmentOS: macOS Monterey(12.3) Ruby ver: ruby 3.1.2p20 httparty ver: 0.20.0 (Python3 - HTTP Request Logging Server) PoC procedure(Linux or MacOS is required.
This is because Windows does not allow file names containing
I write Python code, but any method will work as long as you can see the HTTP Request Body. (e.g. Debugger, HTTP Logging Server, Packet Capture) $ vi logging.py
$ python logging.py
Return Request Header & Body:
Content-Disposition:
References
Golang https://github.com/golang/go/blob/e0e0c8fe9881bbbfe689ad94ca5dddbb252e4233/src/mime/multipart/writer.go#L144 Spring https://github.com/spring-projects/spring-framework/blob/4cc91e46b210b4e4e7ed182f93994511391b54ed/spring-web/src/main/java/org/springframework/http/ContentDisposition.java#L259-L267 Symphony https://github.com/symfony/symfony/blob/123b1651c4a7e219ba59074441badfac65525efe/src/Symfony/Component/Mime/Header/ParameterizedHeader.php#L128-L133 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
0.1.8
0.10.0
0.10.1
0.10.2
0.11.0
+ 67 more Show less
0.12.0
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.15.7
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.0
0.17.1
0.17.3
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.7.0
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
Fixed in
0.21.0
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.15.2
patch
2 CVEs
CVE-2025-68696
GHSA-hm5p-x4rq-38w4
Dec 23, 2025
httparty Has Potential SSRF Vulnerability That Leads to API Key Leakage
High
Network
Low
None
None
SummaryThere may be an SSRF vulnerability in httparty. This issue can pose a risk of leaking API keys, and it can also allow third parties to issue requests to internal servers. DetailsWhen httparty receives a path argument that is an absolute URL, it ignores the Consider the following example of a web application:
Now, suppose an attacker sends a request like this:
In this case, httparty sends the A similar problem was reported and fixed in the HTTP client library axios in the past: Also, Python's PoCFollow these steps to reproduce the issue:
Although Impact
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
0.1.8
0.10.0
0.10.1
0.10.2
0.11.0
+ 72 more Show less
0.12.0
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.15.7
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.0
0.17.1
0.17.3
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.7.0
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
Fixed in
0.24.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-22049
GHSA-5pq7-52mg-hr42
Jan 03, 2023
httparty has multipart/form-data request tampering vulnerability
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
ImpactI found "multipart/form-data request tampering vulnerability" caused by Content-Disposition "filename" lack of escaping in httparty.
https://github.com/jnunemaker/httparty/blob/4416141d37fd71bdba4f37589ec265f55aa446ce/lib/httparty/request/body.rb#L43 By exploiting this problem, the following attacks are possible
For example, this vulnerability can be exploited to generate the following Content-Disposition.
The Abused Header has multiple name ( These problems can result in successful or unsuccessful attacks, depending on the behavior of the parser receiving the request. I have confirmed that the attack succeeds, at least in the following frameworks
The cause of this problem is the lack of escaping of the WhatWG's HTML spec has an escaping requirement. https://html.spec.whatwg.org/#multipart-form-data
PatchesAs noted at the beginning of this section, encoding must be done as described in the HTML Spec. https://html.spec.whatwg.org/#multipart-form-data
Therefore, it is recommended that Content-Disposition be modified by either of the following
https://github.com/jnunemaker/httparty/blob/4416141d37fd71bdba4f37589ec265f55aa446ce/lib/httparty/request/body.rb#L43
Also, as for PoCPoC EnvironmentOS: macOS Monterey(12.3) Ruby ver: ruby 3.1.2p20 httparty ver: 0.20.0 (Python3 - HTTP Request Logging Server) PoC procedure(Linux or MacOS is required.
This is because Windows does not allow file names containing
I write Python code, but any method will work as long as you can see the HTTP Request Body. (e.g. Debugger, HTTP Logging Server, Packet Capture) $ vi logging.py
$ python logging.py
Return Request Header & Body:
Content-Disposition:
References
Golang https://github.com/golang/go/blob/e0e0c8fe9881bbbfe689ad94ca5dddbb252e4233/src/mime/multipart/writer.go#L144 Spring https://github.com/spring-projects/spring-framework/blob/4cc91e46b210b4e4e7ed182f93994511391b54ed/spring-web/src/main/java/org/springframework/http/ContentDisposition.java#L259-L267 Symphony https://github.com/symfony/symfony/blob/123b1651c4a7e219ba59074441badfac65525efe/src/Symfony/Component/Mime/Header/ParameterizedHeader.php#L128-L133 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
0.1.8
0.10.0
0.10.1
0.10.2
0.11.0
+ 67 more Show less
0.12.0
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.15.7
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.0
0.17.1
0.17.3
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.7.0
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
Fixed in
0.21.0
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.15.0
minor
2 CVEs
CVE-2025-68696
GHSA-hm5p-x4rq-38w4
Dec 23, 2025
httparty Has Potential SSRF Vulnerability That Leads to API Key Leakage
High
Network
Low
None
None
SummaryThere may be an SSRF vulnerability in httparty. This issue can pose a risk of leaking API keys, and it can also allow third parties to issue requests to internal servers. DetailsWhen httparty receives a path argument that is an absolute URL, it ignores the Consider the following example of a web application:
Now, suppose an attacker sends a request like this:
In this case, httparty sends the A similar problem was reported and fixed in the HTTP client library axios in the past: Also, Python's PoCFollow these steps to reproduce the issue:
Although Impact
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
0.1.8
0.10.0
0.10.1
0.10.2
0.11.0
+ 72 more Show less
0.12.0
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.15.7
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.0
0.17.1
0.17.3
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.7.0
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
Fixed in
0.24.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-22049
GHSA-5pq7-52mg-hr42
Jan 03, 2023
httparty has multipart/form-data request tampering vulnerability
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
ImpactI found "multipart/form-data request tampering vulnerability" caused by Content-Disposition "filename" lack of escaping in httparty.
https://github.com/jnunemaker/httparty/blob/4416141d37fd71bdba4f37589ec265f55aa446ce/lib/httparty/request/body.rb#L43 By exploiting this problem, the following attacks are possible
For example, this vulnerability can be exploited to generate the following Content-Disposition.
The Abused Header has multiple name ( These problems can result in successful or unsuccessful attacks, depending on the behavior of the parser receiving the request. I have confirmed that the attack succeeds, at least in the following frameworks
The cause of this problem is the lack of escaping of the WhatWG's HTML spec has an escaping requirement. https://html.spec.whatwg.org/#multipart-form-data
PatchesAs noted at the beginning of this section, encoding must be done as described in the HTML Spec. https://html.spec.whatwg.org/#multipart-form-data
Therefore, it is recommended that Content-Disposition be modified by either of the following
https://github.com/jnunemaker/httparty/blob/4416141d37fd71bdba4f37589ec265f55aa446ce/lib/httparty/request/body.rb#L43
Also, as for PoCPoC EnvironmentOS: macOS Monterey(12.3) Ruby ver: ruby 3.1.2p20 httparty ver: 0.20.0 (Python3 - HTTP Request Logging Server) PoC procedure(Linux or MacOS is required.
This is because Windows does not allow file names containing
I write Python code, but any method will work as long as you can see the HTTP Request Body. (e.g. Debugger, HTTP Logging Server, Packet Capture) $ vi logging.py
$ python logging.py
Return Request Header & Body:
Content-Disposition:
References
Golang https://github.com/golang/go/blob/e0e0c8fe9881bbbfe689ad94ca5dddbb252e4233/src/mime/multipart/writer.go#L144 Spring https://github.com/spring-projects/spring-framework/blob/4cc91e46b210b4e4e7ed182f93994511391b54ed/spring-web/src/main/java/org/springframework/http/ContentDisposition.java#L259-L267 Symphony https://github.com/symfony/symfony/blob/123b1651c4a7e219ba59074441badfac65525efe/src/Symfony/Component/Mime/Header/ParameterizedHeader.php#L128-L133 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
0.1.8
0.10.0
0.10.1
0.10.2
0.11.0
+ 67 more Show less
0.12.0
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.15.7
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.0
0.17.1
0.17.3
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.7.0
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
Fixed in
0.21.0
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.14.0
minor
2 CVEs
CVE-2025-68696
GHSA-hm5p-x4rq-38w4
Dec 23, 2025
httparty Has Potential SSRF Vulnerability That Leads to API Key Leakage
High
Network
Low
None
None
SummaryThere may be an SSRF vulnerability in httparty. This issue can pose a risk of leaking API keys, and it can also allow third parties to issue requests to internal servers. DetailsWhen httparty receives a path argument that is an absolute URL, it ignores the Consider the following example of a web application:
Now, suppose an attacker sends a request like this:
In this case, httparty sends the A similar problem was reported and fixed in the HTTP client library axios in the past: Also, Python's PoCFollow these steps to reproduce the issue:
Although Impact
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
0.1.8
0.10.0
0.10.1
0.10.2
0.11.0
+ 72 more Show less
0.12.0
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.15.7
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.0
0.17.1
0.17.3
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.7.0
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
Fixed in
0.24.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-22049
GHSA-5pq7-52mg-hr42
Jan 03, 2023
httparty has multipart/form-data request tampering vulnerability
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
ImpactI found "multipart/form-data request tampering vulnerability" caused by Content-Disposition "filename" lack of escaping in httparty.
https://github.com/jnunemaker/httparty/blob/4416141d37fd71bdba4f37589ec265f55aa446ce/lib/httparty/request/body.rb#L43 By exploiting this problem, the following attacks are possible
For example, this vulnerability can be exploited to generate the following Content-Disposition.
The Abused Header has multiple name ( These problems can result in successful or unsuccessful attacks, depending on the behavior of the parser receiving the request. I have confirmed that the attack succeeds, at least in the following frameworks
The cause of this problem is the lack of escaping of the WhatWG's HTML spec has an escaping requirement. https://html.spec.whatwg.org/#multipart-form-data
PatchesAs noted at the beginning of this section, encoding must be done as described in the HTML Spec. https://html.spec.whatwg.org/#multipart-form-data
Therefore, it is recommended that Content-Disposition be modified by either of the following
https://github.com/jnunemaker/httparty/blob/4416141d37fd71bdba4f37589ec265f55aa446ce/lib/httparty/request/body.rb#L43
Also, as for PoCPoC EnvironmentOS: macOS Monterey(12.3) Ruby ver: ruby 3.1.2p20 httparty ver: 0.20.0 (Python3 - HTTP Request Logging Server) PoC procedure(Linux or MacOS is required.
This is because Windows does not allow file names containing
I write Python code, but any method will work as long as you can see the HTTP Request Body. (e.g. Debugger, HTTP Logging Server, Packet Capture) $ vi logging.py
$ python logging.py
Return Request Header & Body:
Content-Disposition:
References
Golang https://github.com/golang/go/blob/e0e0c8fe9881bbbfe689ad94ca5dddbb252e4233/src/mime/multipart/writer.go#L144 Spring https://github.com/spring-projects/spring-framework/blob/4cc91e46b210b4e4e7ed182f93994511391b54ed/spring-web/src/main/java/org/springframework/http/ContentDisposition.java#L259-L267 Symphony https://github.com/symfony/symfony/blob/123b1651c4a7e219ba59074441badfac65525efe/src/Symfony/Component/Mime/Header/ParameterizedHeader.php#L128-L133 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
0.1.8
0.10.0
0.10.1
0.10.2
0.11.0
+ 67 more Show less
0.12.0
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.15.7
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.0
0.17.1
0.17.3
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.7.0
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
Fixed in
0.21.0
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.13.7
patch
2 CVEs
CVE-2025-68696
GHSA-hm5p-x4rq-38w4
Dec 23, 2025
httparty Has Potential SSRF Vulnerability That Leads to API Key Leakage
High
Network
Low
None
None
SummaryThere may be an SSRF vulnerability in httparty. This issue can pose a risk of leaking API keys, and it can also allow third parties to issue requests to internal servers. DetailsWhen httparty receives a path argument that is an absolute URL, it ignores the Consider the following example of a web application:
Now, suppose an attacker sends a request like this:
In this case, httparty sends the A similar problem was reported and fixed in the HTTP client library axios in the past: Also, Python's PoCFollow these steps to reproduce the issue:
Although Impact
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
0.1.8
0.10.0
0.10.1
0.10.2
0.11.0
+ 72 more Show less
0.12.0
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.15.7
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.0
0.17.1
0.17.3
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.7.0
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
Fixed in
0.24.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-22049
GHSA-5pq7-52mg-hr42
Jan 03, 2023
httparty has multipart/form-data request tampering vulnerability
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
ImpactI found "multipart/form-data request tampering vulnerability" caused by Content-Disposition "filename" lack of escaping in httparty.
https://github.com/jnunemaker/httparty/blob/4416141d37fd71bdba4f37589ec265f55aa446ce/lib/httparty/request/body.rb#L43 By exploiting this problem, the following attacks are possible
For example, this vulnerability can be exploited to generate the following Content-Disposition.
The Abused Header has multiple name ( These problems can result in successful or unsuccessful attacks, depending on the behavior of the parser receiving the request. I have confirmed that the attack succeeds, at least in the following frameworks
The cause of this problem is the lack of escaping of the WhatWG's HTML spec has an escaping requirement. https://html.spec.whatwg.org/#multipart-form-data
PatchesAs noted at the beginning of this section, encoding must be done as described in the HTML Spec. https://html.spec.whatwg.org/#multipart-form-data
Therefore, it is recommended that Content-Disposition be modified by either of the following
https://github.com/jnunemaker/httparty/blob/4416141d37fd71bdba4f37589ec265f55aa446ce/lib/httparty/request/body.rb#L43
Also, as for PoCPoC EnvironmentOS: macOS Monterey(12.3) Ruby ver: ruby 3.1.2p20 httparty ver: 0.20.0 (Python3 - HTTP Request Logging Server) PoC procedure(Linux or MacOS is required.
This is because Windows does not allow file names containing
I write Python code, but any method will work as long as you can see the HTTP Request Body. (e.g. Debugger, HTTP Logging Server, Packet Capture) $ vi logging.py
$ python logging.py
Return Request Header & Body:
Content-Disposition:
References
Golang https://github.com/golang/go/blob/e0e0c8fe9881bbbfe689ad94ca5dddbb252e4233/src/mime/multipart/writer.go#L144 Spring https://github.com/spring-projects/spring-framework/blob/4cc91e46b210b4e4e7ed182f93994511391b54ed/spring-web/src/main/java/org/springframework/http/ContentDisposition.java#L259-L267 Symphony https://github.com/symfony/symfony/blob/123b1651c4a7e219ba59074441badfac65525efe/src/Symfony/Component/Mime/Header/ParameterizedHeader.php#L128-L133 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
0.1.8
0.10.0
0.10.1
0.10.2
0.11.0
+ 67 more Show less
0.12.0
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.15.7
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.0
0.17.1
0.17.3
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.7.0
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
Fixed in
0.21.0
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.13.6
patch
2 CVEs
CVE-2025-68696
GHSA-hm5p-x4rq-38w4
Dec 23, 2025
httparty Has Potential SSRF Vulnerability That Leads to API Key Leakage
High
Network
Low
None
None
SummaryThere may be an SSRF vulnerability in httparty. This issue can pose a risk of leaking API keys, and it can also allow third parties to issue requests to internal servers. DetailsWhen httparty receives a path argument that is an absolute URL, it ignores the Consider the following example of a web application:
Now, suppose an attacker sends a request like this:
In this case, httparty sends the A similar problem was reported and fixed in the HTTP client library axios in the past: Also, Python's PoCFollow these steps to reproduce the issue:
Although Impact
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
0.1.8
0.10.0
0.10.1
0.10.2
0.11.0
+ 72 more Show less
0.12.0
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.15.7
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.0
0.17.1
0.17.3
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.7.0
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
Fixed in
0.24.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-22049
GHSA-5pq7-52mg-hr42
Jan 03, 2023
httparty has multipart/form-data request tampering vulnerability
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
ImpactI found "multipart/form-data request tampering vulnerability" caused by Content-Disposition "filename" lack of escaping in httparty.
https://github.com/jnunemaker/httparty/blob/4416141d37fd71bdba4f37589ec265f55aa446ce/lib/httparty/request/body.rb#L43 By exploiting this problem, the following attacks are possible
For example, this vulnerability can be exploited to generate the following Content-Disposition.
The Abused Header has multiple name ( These problems can result in successful or unsuccessful attacks, depending on the behavior of the parser receiving the request. I have confirmed that the attack succeeds, at least in the following frameworks
The cause of this problem is the lack of escaping of the WhatWG's HTML spec has an escaping requirement. https://html.spec.whatwg.org/#multipart-form-data
PatchesAs noted at the beginning of this section, encoding must be done as described in the HTML Spec. https://html.spec.whatwg.org/#multipart-form-data
Therefore, it is recommended that Content-Disposition be modified by either of the following
https://github.com/jnunemaker/httparty/blob/4416141d37fd71bdba4f37589ec265f55aa446ce/lib/httparty/request/body.rb#L43
Also, as for PoCPoC EnvironmentOS: macOS Monterey(12.3) Ruby ver: ruby 3.1.2p20 httparty ver: 0.20.0 (Python3 - HTTP Request Logging Server) PoC procedure(Linux or MacOS is required.
This is because Windows does not allow file names containing
I write Python code, but any method will work as long as you can see the HTTP Request Body. (e.g. Debugger, HTTP Logging Server, Packet Capture) $ vi logging.py
$ python logging.py
Return Request Header & Body:
Content-Disposition:
References
Golang https://github.com/golang/go/blob/e0e0c8fe9881bbbfe689ad94ca5dddbb252e4233/src/mime/multipart/writer.go#L144 Spring https://github.com/spring-projects/spring-framework/blob/4cc91e46b210b4e4e7ed182f93994511391b54ed/spring-web/src/main/java/org/springframework/http/ContentDisposition.java#L259-L267 Symphony https://github.com/symfony/symfony/blob/123b1651c4a7e219ba59074441badfac65525efe/src/Symfony/Component/Mime/Header/ParameterizedHeader.php#L128-L133 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
0.1.8
0.10.0
0.10.1
0.10.2
0.11.0
+ 67 more Show less
0.12.0
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.15.7
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.0
0.17.1
0.17.3
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.7.0
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
Fixed in
0.21.0
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.13.5
patch
2 CVEs
CVE-2025-68696
GHSA-hm5p-x4rq-38w4
Dec 23, 2025
httparty Has Potential SSRF Vulnerability That Leads to API Key Leakage
High
Network
Low
None
None
SummaryThere may be an SSRF vulnerability in httparty. This issue can pose a risk of leaking API keys, and it can also allow third parties to issue requests to internal servers. DetailsWhen httparty receives a path argument that is an absolute URL, it ignores the Consider the following example of a web application:
Now, suppose an attacker sends a request like this:
In this case, httparty sends the A similar problem was reported and fixed in the HTTP client library axios in the past: Also, Python's PoCFollow these steps to reproduce the issue:
Although Impact
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
0.1.8
0.10.0
0.10.1
0.10.2
0.11.0
+ 72 more Show less
0.12.0
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.15.7
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.0
0.17.1
0.17.3
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.7.0
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
Fixed in
0.24.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-22049
GHSA-5pq7-52mg-hr42
Jan 03, 2023
httparty has multipart/form-data request tampering vulnerability
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
ImpactI found "multipart/form-data request tampering vulnerability" caused by Content-Disposition "filename" lack of escaping in httparty.
https://github.com/jnunemaker/httparty/blob/4416141d37fd71bdba4f37589ec265f55aa446ce/lib/httparty/request/body.rb#L43 By exploiting this problem, the following attacks are possible
For example, this vulnerability can be exploited to generate the following Content-Disposition.
The Abused Header has multiple name ( These problems can result in successful or unsuccessful attacks, depending on the behavior of the parser receiving the request. I have confirmed that the attack succeeds, at least in the following frameworks
The cause of this problem is the lack of escaping of the WhatWG's HTML spec has an escaping requirement. https://html.spec.whatwg.org/#multipart-form-data
PatchesAs noted at the beginning of this section, encoding must be done as described in the HTML Spec. https://html.spec.whatwg.org/#multipart-form-data
Therefore, it is recommended that Content-Disposition be modified by either of the following
https://github.com/jnunemaker/httparty/blob/4416141d37fd71bdba4f37589ec265f55aa446ce/lib/httparty/request/body.rb#L43
Also, as for PoCPoC EnvironmentOS: macOS Monterey(12.3) Ruby ver: ruby 3.1.2p20 httparty ver: 0.20.0 (Python3 - HTTP Request Logging Server) PoC procedure(Linux or MacOS is required.
This is because Windows does not allow file names containing
I write Python code, but any method will work as long as you can see the HTTP Request Body. (e.g. Debugger, HTTP Logging Server, Packet Capture) $ vi logging.py
$ python logging.py
Return Request Header & Body:
Content-Disposition:
References
Golang https://github.com/golang/go/blob/e0e0c8fe9881bbbfe689ad94ca5dddbb252e4233/src/mime/multipart/writer.go#L144 Spring https://github.com/spring-projects/spring-framework/blob/4cc91e46b210b4e4e7ed182f93994511391b54ed/spring-web/src/main/java/org/springframework/http/ContentDisposition.java#L259-L267 Symphony https://github.com/symfony/symfony/blob/123b1651c4a7e219ba59074441badfac65525efe/src/Symfony/Component/Mime/Header/ParameterizedHeader.php#L128-L133 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
0.1.8
0.10.0
0.10.1
0.10.2
0.11.0
+ 67 more Show less
0.12.0
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.15.7
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.0
0.17.1
0.17.3
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.7.0
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
Fixed in
0.21.0
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.13.4
patch
2 CVEs
CVE-2025-68696
GHSA-hm5p-x4rq-38w4
Dec 23, 2025
httparty Has Potential SSRF Vulnerability That Leads to API Key Leakage
High
Network
Low
None
None
SummaryThere may be an SSRF vulnerability in httparty. This issue can pose a risk of leaking API keys, and it can also allow third parties to issue requests to internal servers. DetailsWhen httparty receives a path argument that is an absolute URL, it ignores the Consider the following example of a web application:
Now, suppose an attacker sends a request like this:
In this case, httparty sends the A similar problem was reported and fixed in the HTTP client library axios in the past: Also, Python's PoCFollow these steps to reproduce the issue:
Although Impact
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
0.1.8
0.10.0
0.10.1
0.10.2
0.11.0
+ 72 more Show less
0.12.0
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.15.7
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.0
0.17.1
0.17.3
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.7.0
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
Fixed in
0.24.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-22049
GHSA-5pq7-52mg-hr42
Jan 03, 2023
httparty has multipart/form-data request tampering vulnerability
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
ImpactI found "multipart/form-data request tampering vulnerability" caused by Content-Disposition "filename" lack of escaping in httparty.
https://github.com/jnunemaker/httparty/blob/4416141d37fd71bdba4f37589ec265f55aa446ce/lib/httparty/request/body.rb#L43 By exploiting this problem, the following attacks are possible
For example, this vulnerability can be exploited to generate the following Content-Disposition.
The Abused Header has multiple name ( These problems can result in successful or unsuccessful attacks, depending on the behavior of the parser receiving the request. I have confirmed that the attack succeeds, at least in the following frameworks
The cause of this problem is the lack of escaping of the WhatWG's HTML spec has an escaping requirement. https://html.spec.whatwg.org/#multipart-form-data
PatchesAs noted at the beginning of this section, encoding must be done as described in the HTML Spec. https://html.spec.whatwg.org/#multipart-form-data
Therefore, it is recommended that Content-Disposition be modified by either of the following
https://github.com/jnunemaker/httparty/blob/4416141d37fd71bdba4f37589ec265f55aa446ce/lib/httparty/request/body.rb#L43
Also, as for PoCPoC EnvironmentOS: macOS Monterey(12.3) Ruby ver: ruby 3.1.2p20 httparty ver: 0.20.0 (Python3 - HTTP Request Logging Server) PoC procedure(Linux or MacOS is required.
This is because Windows does not allow file names containing
I write Python code, but any method will work as long as you can see the HTTP Request Body. (e.g. Debugger, HTTP Logging Server, Packet Capture) $ vi logging.py
$ python logging.py
Return Request Header & Body:
Content-Disposition:
References
Golang https://github.com/golang/go/blob/e0e0c8fe9881bbbfe689ad94ca5dddbb252e4233/src/mime/multipart/writer.go#L144 Spring https://github.com/spring-projects/spring-framework/blob/4cc91e46b210b4e4e7ed182f93994511391b54ed/spring-web/src/main/java/org/springframework/http/ContentDisposition.java#L259-L267 Symphony https://github.com/symfony/symfony/blob/123b1651c4a7e219ba59074441badfac65525efe/src/Symfony/Component/Mime/Header/ParameterizedHeader.php#L128-L133 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
0.1.8
0.10.0
0.10.1
0.10.2
0.11.0
+ 67 more Show less
0.12.0
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.15.7
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.0
0.17.1
0.17.3
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.7.0
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
Fixed in
0.21.0
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.13.3
patch
2 CVEs
CVE-2025-68696
GHSA-hm5p-x4rq-38w4
Dec 23, 2025
httparty Has Potential SSRF Vulnerability That Leads to API Key Leakage
High
Network
Low
None
None
SummaryThere may be an SSRF vulnerability in httparty. This issue can pose a risk of leaking API keys, and it can also allow third parties to issue requests to internal servers. DetailsWhen httparty receives a path argument that is an absolute URL, it ignores the Consider the following example of a web application:
Now, suppose an attacker sends a request like this:
In this case, httparty sends the A similar problem was reported and fixed in the HTTP client library axios in the past: Also, Python's PoCFollow these steps to reproduce the issue:
Although Impact
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
0.1.8
0.10.0
0.10.1
0.10.2
0.11.0
+ 72 more Show less
0.12.0
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.15.7
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.0
0.17.1
0.17.3
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.7.0
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
Fixed in
0.24.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-22049
GHSA-5pq7-52mg-hr42
Jan 03, 2023
httparty has multipart/form-data request tampering vulnerability
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
ImpactI found "multipart/form-data request tampering vulnerability" caused by Content-Disposition "filename" lack of escaping in httparty.
https://github.com/jnunemaker/httparty/blob/4416141d37fd71bdba4f37589ec265f55aa446ce/lib/httparty/request/body.rb#L43 By exploiting this problem, the following attacks are possible
For example, this vulnerability can be exploited to generate the following Content-Disposition.
The Abused Header has multiple name ( These problems can result in successful or unsuccessful attacks, depending on the behavior of the parser receiving the request. I have confirmed that the attack succeeds, at least in the following frameworks
The cause of this problem is the lack of escaping of the WhatWG's HTML spec has an escaping requirement. https://html.spec.whatwg.org/#multipart-form-data
PatchesAs noted at the beginning of this section, encoding must be done as described in the HTML Spec. https://html.spec.whatwg.org/#multipart-form-data
Therefore, it is recommended that Content-Disposition be modified by either of the following
https://github.com/jnunemaker/httparty/blob/4416141d37fd71bdba4f37589ec265f55aa446ce/lib/httparty/request/body.rb#L43
Also, as for PoCPoC EnvironmentOS: macOS Monterey(12.3) Ruby ver: ruby 3.1.2p20 httparty ver: 0.20.0 (Python3 - HTTP Request Logging Server) PoC procedure(Linux or MacOS is required.
This is because Windows does not allow file names containing
I write Python code, but any method will work as long as you can see the HTTP Request Body. (e.g. Debugger, HTTP Logging Server, Packet Capture) $ vi logging.py
$ python logging.py
Return Request Header & Body:
Content-Disposition:
References
Golang https://github.com/golang/go/blob/e0e0c8fe9881bbbfe689ad94ca5dddbb252e4233/src/mime/multipart/writer.go#L144 Spring https://github.com/spring-projects/spring-framework/blob/4cc91e46b210b4e4e7ed182f93994511391b54ed/spring-web/src/main/java/org/springframework/http/ContentDisposition.java#L259-L267 Symphony https://github.com/symfony/symfony/blob/123b1651c4a7e219ba59074441badfac65525efe/src/Symfony/Component/Mime/Header/ParameterizedHeader.php#L128-L133 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
0.1.8
0.10.0
0.10.1
0.10.2
0.11.0
+ 67 more Show less
0.12.0
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.15.7
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.0
0.17.1
0.17.3
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.7.0
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
Fixed in
0.21.0
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.13.2
patch
2 CVEs
CVE-2025-68696
GHSA-hm5p-x4rq-38w4
Dec 23, 2025
httparty Has Potential SSRF Vulnerability That Leads to API Key Leakage
High
Network
Low
None
None
SummaryThere may be an SSRF vulnerability in httparty. This issue can pose a risk of leaking API keys, and it can also allow third parties to issue requests to internal servers. DetailsWhen httparty receives a path argument that is an absolute URL, it ignores the Consider the following example of a web application:
Now, suppose an attacker sends a request like this:
In this case, httparty sends the A similar problem was reported and fixed in the HTTP client library axios in the past: Also, Python's PoCFollow these steps to reproduce the issue:
Although Impact
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
0.1.8
0.10.0
0.10.1
0.10.2
0.11.0
+ 72 more Show less
0.12.0
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.15.7
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.0
0.17.1
0.17.3
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.7.0
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
Fixed in
0.24.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-22049
GHSA-5pq7-52mg-hr42
Jan 03, 2023
httparty has multipart/form-data request tampering vulnerability
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
ImpactI found "multipart/form-data request tampering vulnerability" caused by Content-Disposition "filename" lack of escaping in httparty.
https://github.com/jnunemaker/httparty/blob/4416141d37fd71bdba4f37589ec265f55aa446ce/lib/httparty/request/body.rb#L43 By exploiting this problem, the following attacks are possible
For example, this vulnerability can be exploited to generate the following Content-Disposition.
The Abused Header has multiple name ( These problems can result in successful or unsuccessful attacks, depending on the behavior of the parser receiving the request. I have confirmed that the attack succeeds, at least in the following frameworks
The cause of this problem is the lack of escaping of the WhatWG's HTML spec has an escaping requirement. https://html.spec.whatwg.org/#multipart-form-data
PatchesAs noted at the beginning of this section, encoding must be done as described in the HTML Spec. https://html.spec.whatwg.org/#multipart-form-data
Therefore, it is recommended that Content-Disposition be modified by either of the following
https://github.com/jnunemaker/httparty/blob/4416141d37fd71bdba4f37589ec265f55aa446ce/lib/httparty/request/body.rb#L43
Also, as for PoCPoC EnvironmentOS: macOS Monterey(12.3) Ruby ver: ruby 3.1.2p20 httparty ver: 0.20.0 (Python3 - HTTP Request Logging Server) PoC procedure(Linux or MacOS is required.
This is because Windows does not allow file names containing
I write Python code, but any method will work as long as you can see the HTTP Request Body. (e.g. Debugger, HTTP Logging Server, Packet Capture) $ vi logging.py
$ python logging.py
Return Request Header & Body:
Content-Disposition:
References
Golang https://github.com/golang/go/blob/e0e0c8fe9881bbbfe689ad94ca5dddbb252e4233/src/mime/multipart/writer.go#L144 Spring https://github.com/spring-projects/spring-framework/blob/4cc91e46b210b4e4e7ed182f93994511391b54ed/spring-web/src/main/java/org/springframework/http/ContentDisposition.java#L259-L267 Symphony https://github.com/symfony/symfony/blob/123b1651c4a7e219ba59074441badfac65525efe/src/Symfony/Component/Mime/Header/ParameterizedHeader.php#L128-L133 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
0.1.8
0.10.0
0.10.1
0.10.2
0.11.0
+ 67 more Show less
0.12.0
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.15.7
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.0
0.17.1
0.17.3
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.7.0
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
Fixed in
0.21.0
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.13.1
patch
2 CVEs
CVE-2025-68696
GHSA-hm5p-x4rq-38w4
Dec 23, 2025
httparty Has Potential SSRF Vulnerability That Leads to API Key Leakage
High
Network
Low
None
None
SummaryThere may be an SSRF vulnerability in httparty. This issue can pose a risk of leaking API keys, and it can also allow third parties to issue requests to internal servers. DetailsWhen httparty receives a path argument that is an absolute URL, it ignores the Consider the following example of a web application:
Now, suppose an attacker sends a request like this:
In this case, httparty sends the A similar problem was reported and fixed in the HTTP client library axios in the past: Also, Python's PoCFollow these steps to reproduce the issue:
Although Impact
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
0.1.8
0.10.0
0.10.1
0.10.2
0.11.0
+ 72 more Show less
0.12.0
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.15.7
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.0
0.17.1
0.17.3
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.7.0
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
Fixed in
0.24.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-22049
GHSA-5pq7-52mg-hr42
Jan 03, 2023
httparty has multipart/form-data request tampering vulnerability
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
ImpactI found "multipart/form-data request tampering vulnerability" caused by Content-Disposition "filename" lack of escaping in httparty.
https://github.com/jnunemaker/httparty/blob/4416141d37fd71bdba4f37589ec265f55aa446ce/lib/httparty/request/body.rb#L43 By exploiting this problem, the following attacks are possible
For example, this vulnerability can be exploited to generate the following Content-Disposition.
The Abused Header has multiple name ( These problems can result in successful or unsuccessful attacks, depending on the behavior of the parser receiving the request. I have confirmed that the attack succeeds, at least in the following frameworks
The cause of this problem is the lack of escaping of the WhatWG's HTML spec has an escaping requirement. https://html.spec.whatwg.org/#multipart-form-data
PatchesAs noted at the beginning of this section, encoding must be done as described in the HTML Spec. https://html.spec.whatwg.org/#multipart-form-data
Therefore, it is recommended that Content-Disposition be modified by either of the following
https://github.com/jnunemaker/httparty/blob/4416141d37fd71bdba4f37589ec265f55aa446ce/lib/httparty/request/body.rb#L43
Also, as for PoCPoC EnvironmentOS: macOS Monterey(12.3) Ruby ver: ruby 3.1.2p20 httparty ver: 0.20.0 (Python3 - HTTP Request Logging Server) PoC procedure(Linux or MacOS is required.
This is because Windows does not allow file names containing
I write Python code, but any method will work as long as you can see the HTTP Request Body. (e.g. Debugger, HTTP Logging Server, Packet Capture) $ vi logging.py
$ python logging.py
Return Request Header & Body:
Content-Disposition:
References
Golang https://github.com/golang/go/blob/e0e0c8fe9881bbbfe689ad94ca5dddbb252e4233/src/mime/multipart/writer.go#L144 Spring https://github.com/spring-projects/spring-framework/blob/4cc91e46b210b4e4e7ed182f93994511391b54ed/spring-web/src/main/java/org/springframework/http/ContentDisposition.java#L259-L267 Symphony https://github.com/symfony/symfony/blob/123b1651c4a7e219ba59074441badfac65525efe/src/Symfony/Component/Mime/Header/ParameterizedHeader.php#L128-L133 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
0.1.8
0.10.0
0.10.1
0.10.2
0.11.0
+ 67 more Show less
0.12.0
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.15.7
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.0
0.17.1
0.17.3
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.7.0
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
Fixed in
0.21.0
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.13.0
minor
2 CVEs
CVE-2025-68696
GHSA-hm5p-x4rq-38w4
Dec 23, 2025
httparty Has Potential SSRF Vulnerability That Leads to API Key Leakage
High
Network
Low
None
None
SummaryThere may be an SSRF vulnerability in httparty. This issue can pose a risk of leaking API keys, and it can also allow third parties to issue requests to internal servers. DetailsWhen httparty receives a path argument that is an absolute URL, it ignores the Consider the following example of a web application:
Now, suppose an attacker sends a request like this:
In this case, httparty sends the A similar problem was reported and fixed in the HTTP client library axios in the past: Also, Python's PoCFollow these steps to reproduce the issue:
Although Impact
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
0.1.8
0.10.0
0.10.1
0.10.2
0.11.0
+ 72 more Show less
0.12.0
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.15.7
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.0
0.17.1
0.17.3
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.7.0
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
Fixed in
0.24.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-22049
GHSA-5pq7-52mg-hr42
Jan 03, 2023
httparty has multipart/form-data request tampering vulnerability
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
ImpactI found "multipart/form-data request tampering vulnerability" caused by Content-Disposition "filename" lack of escaping in httparty.
https://github.com/jnunemaker/httparty/blob/4416141d37fd71bdba4f37589ec265f55aa446ce/lib/httparty/request/body.rb#L43 By exploiting this problem, the following attacks are possible
For example, this vulnerability can be exploited to generate the following Content-Disposition.
The Abused Header has multiple name ( These problems can result in successful or unsuccessful attacks, depending on the behavior of the parser receiving the request. I have confirmed that the attack succeeds, at least in the following frameworks
The cause of this problem is the lack of escaping of the WhatWG's HTML spec has an escaping requirement. https://html.spec.whatwg.org/#multipart-form-data
PatchesAs noted at the beginning of this section, encoding must be done as described in the HTML Spec. https://html.spec.whatwg.org/#multipart-form-data
Therefore, it is recommended that Content-Disposition be modified by either of the following
https://github.com/jnunemaker/httparty/blob/4416141d37fd71bdba4f37589ec265f55aa446ce/lib/httparty/request/body.rb#L43
Also, as for PoCPoC EnvironmentOS: macOS Monterey(12.3) Ruby ver: ruby 3.1.2p20 httparty ver: 0.20.0 (Python3 - HTTP Request Logging Server) PoC procedure(Linux or MacOS is required.
This is because Windows does not allow file names containing
I write Python code, but any method will work as long as you can see the HTTP Request Body. (e.g. Debugger, HTTP Logging Server, Packet Capture) $ vi logging.py
$ python logging.py
Return Request Header & Body:
Content-Disposition:
References
Golang https://github.com/golang/go/blob/e0e0c8fe9881bbbfe689ad94ca5dddbb252e4233/src/mime/multipart/writer.go#L144 Spring https://github.com/spring-projects/spring-framework/blob/4cc91e46b210b4e4e7ed182f93994511391b54ed/spring-web/src/main/java/org/springframework/http/ContentDisposition.java#L259-L267 Symphony https://github.com/symfony/symfony/blob/123b1651c4a7e219ba59074441badfac65525efe/src/Symfony/Component/Mime/Header/ParameterizedHeader.php#L128-L133 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
0.1.8
0.10.0
0.10.1
0.10.2
0.11.0
+ 67 more Show less
0.12.0
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.15.7
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.0
0.17.1
0.17.3
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.7.0
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
Fixed in
0.21.0
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.12.0
minor
2 CVEs
CVE-2025-68696
GHSA-hm5p-x4rq-38w4
Dec 23, 2025
httparty Has Potential SSRF Vulnerability That Leads to API Key Leakage
High
Network
Low
None
None
SummaryThere may be an SSRF vulnerability in httparty. This issue can pose a risk of leaking API keys, and it can also allow third parties to issue requests to internal servers. DetailsWhen httparty receives a path argument that is an absolute URL, it ignores the Consider the following example of a web application:
Now, suppose an attacker sends a request like this:
In this case, httparty sends the A similar problem was reported and fixed in the HTTP client library axios in the past: Also, Python's PoCFollow these steps to reproduce the issue:
Although Impact
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
0.1.8
0.10.0
0.10.1
0.10.2
0.11.0
+ 72 more Show less
0.12.0
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.15.7
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.0
0.17.1
0.17.3
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.7.0
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
Fixed in
0.24.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-22049
GHSA-5pq7-52mg-hr42
Jan 03, 2023
httparty has multipart/form-data request tampering vulnerability
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
ImpactI found "multipart/form-data request tampering vulnerability" caused by Content-Disposition "filename" lack of escaping in httparty.
https://github.com/jnunemaker/httparty/blob/4416141d37fd71bdba4f37589ec265f55aa446ce/lib/httparty/request/body.rb#L43 By exploiting this problem, the following attacks are possible
For example, this vulnerability can be exploited to generate the following Content-Disposition.
The Abused Header has multiple name ( These problems can result in successful or unsuccessful attacks, depending on the behavior of the parser receiving the request. I have confirmed that the attack succeeds, at least in the following frameworks
The cause of this problem is the lack of escaping of the WhatWG's HTML spec has an escaping requirement. https://html.spec.whatwg.org/#multipart-form-data
PatchesAs noted at the beginning of this section, encoding must be done as described in the HTML Spec. https://html.spec.whatwg.org/#multipart-form-data
Therefore, it is recommended that Content-Disposition be modified by either of the following
https://github.com/jnunemaker/httparty/blob/4416141d37fd71bdba4f37589ec265f55aa446ce/lib/httparty/request/body.rb#L43
Also, as for PoCPoC EnvironmentOS: macOS Monterey(12.3) Ruby ver: ruby 3.1.2p20 httparty ver: 0.20.0 (Python3 - HTTP Request Logging Server) PoC procedure(Linux or MacOS is required.
This is because Windows does not allow file names containing
I write Python code, but any method will work as long as you can see the HTTP Request Body. (e.g. Debugger, HTTP Logging Server, Packet Capture) $ vi logging.py
$ python logging.py
Return Request Header & Body:
Content-Disposition:
References
Golang https://github.com/golang/go/blob/e0e0c8fe9881bbbfe689ad94ca5dddbb252e4233/src/mime/multipart/writer.go#L144 Spring https://github.com/spring-projects/spring-framework/blob/4cc91e46b210b4e4e7ed182f93994511391b54ed/spring-web/src/main/java/org/springframework/http/ContentDisposition.java#L259-L267 Symphony https://github.com/symfony/symfony/blob/123b1651c4a7e219ba59074441badfac65525efe/src/Symfony/Component/Mime/Header/ParameterizedHeader.php#L128-L133 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
0.1.8
0.10.0
0.10.1
0.10.2
0.11.0
+ 67 more Show less
0.12.0
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.15.7
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.0
0.17.1
0.17.3
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.7.0
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
Fixed in
0.21.0
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.11.0
minor
2 CVEs
CVE-2025-68696
GHSA-hm5p-x4rq-38w4
Dec 23, 2025
httparty Has Potential SSRF Vulnerability That Leads to API Key Leakage
High
Network
Low
None
None
SummaryThere may be an SSRF vulnerability in httparty. This issue can pose a risk of leaking API keys, and it can also allow third parties to issue requests to internal servers. DetailsWhen httparty receives a path argument that is an absolute URL, it ignores the Consider the following example of a web application:
Now, suppose an attacker sends a request like this:
In this case, httparty sends the A similar problem was reported and fixed in the HTTP client library axios in the past: Also, Python's PoCFollow these steps to reproduce the issue:
Although Impact
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
0.1.8
0.10.0
0.10.1
0.10.2
0.11.0
+ 72 more Show less
0.12.0
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.15.7
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.0
0.17.1
0.17.3
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.7.0
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
Fixed in
0.24.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-22049
GHSA-5pq7-52mg-hr42
Jan 03, 2023
httparty has multipart/form-data request tampering vulnerability
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
ImpactI found "multipart/form-data request tampering vulnerability" caused by Content-Disposition "filename" lack of escaping in httparty.
https://github.com/jnunemaker/httparty/blob/4416141d37fd71bdba4f37589ec265f55aa446ce/lib/httparty/request/body.rb#L43 By exploiting this problem, the following attacks are possible
For example, this vulnerability can be exploited to generate the following Content-Disposition.
The Abused Header has multiple name ( These problems can result in successful or unsuccessful attacks, depending on the behavior of the parser receiving the request. I have confirmed that the attack succeeds, at least in the following frameworks
The cause of this problem is the lack of escaping of the WhatWG's HTML spec has an escaping requirement. https://html.spec.whatwg.org/#multipart-form-data
PatchesAs noted at the beginning of this section, encoding must be done as described in the HTML Spec. https://html.spec.whatwg.org/#multipart-form-data
Therefore, it is recommended that Content-Disposition be modified by either of the following
https://github.com/jnunemaker/httparty/blob/4416141d37fd71bdba4f37589ec265f55aa446ce/lib/httparty/request/body.rb#L43
Also, as for PoCPoC EnvironmentOS: macOS Monterey(12.3) Ruby ver: ruby 3.1.2p20 httparty ver: 0.20.0 (Python3 - HTTP Request Logging Server) PoC procedure(Linux or MacOS is required.
This is because Windows does not allow file names containing
I write Python code, but any method will work as long as you can see the HTTP Request Body. (e.g. Debugger, HTTP Logging Server, Packet Capture) $ vi logging.py
$ python logging.py
Return Request Header & Body:
Content-Disposition:
References
Golang https://github.com/golang/go/blob/e0e0c8fe9881bbbfe689ad94ca5dddbb252e4233/src/mime/multipart/writer.go#L144 Spring https://github.com/spring-projects/spring-framework/blob/4cc91e46b210b4e4e7ed182f93994511391b54ed/spring-web/src/main/java/org/springframework/http/ContentDisposition.java#L259-L267 Symphony https://github.com/symfony/symfony/blob/123b1651c4a7e219ba59074441badfac65525efe/src/Symfony/Component/Mime/Header/ParameterizedHeader.php#L128-L133 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
0.1.8
0.10.0
0.10.1
0.10.2
0.11.0
+ 67 more Show less
0.12.0
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.15.7
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.0
0.17.1
0.17.3
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.7.0
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
Fixed in
0.21.0
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.10.2
patch
2 CVEs
CVE-2025-68696
GHSA-hm5p-x4rq-38w4
Dec 23, 2025
httparty Has Potential SSRF Vulnerability That Leads to API Key Leakage
High
Network
Low
None
None
SummaryThere may be an SSRF vulnerability in httparty. This issue can pose a risk of leaking API keys, and it can also allow third parties to issue requests to internal servers. DetailsWhen httparty receives a path argument that is an absolute URL, it ignores the Consider the following example of a web application:
Now, suppose an attacker sends a request like this:
In this case, httparty sends the A similar problem was reported and fixed in the HTTP client library axios in the past: Also, Python's PoCFollow these steps to reproduce the issue:
Although Impact
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
0.1.8
0.10.0
0.10.1
0.10.2
0.11.0
+ 72 more Show less
0.12.0
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.15.7
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.0
0.17.1
0.17.3
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.7.0
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
Fixed in
0.24.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-22049
GHSA-5pq7-52mg-hr42
Jan 03, 2023
httparty has multipart/form-data request tampering vulnerability
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
ImpactI found "multipart/form-data request tampering vulnerability" caused by Content-Disposition "filename" lack of escaping in httparty.
https://github.com/jnunemaker/httparty/blob/4416141d37fd71bdba4f37589ec265f55aa446ce/lib/httparty/request/body.rb#L43 By exploiting this problem, the following attacks are possible
For example, this vulnerability can be exploited to generate the following Content-Disposition.
The Abused Header has multiple name ( These problems can result in successful or unsuccessful attacks, depending on the behavior of the parser receiving the request. I have confirmed that the attack succeeds, at least in the following frameworks
The cause of this problem is the lack of escaping of the WhatWG's HTML spec has an escaping requirement. https://html.spec.whatwg.org/#multipart-form-data
PatchesAs noted at the beginning of this section, encoding must be done as described in the HTML Spec. https://html.spec.whatwg.org/#multipart-form-data
Therefore, it is recommended that Content-Disposition be modified by either of the following
https://github.com/jnunemaker/httparty/blob/4416141d37fd71bdba4f37589ec265f55aa446ce/lib/httparty/request/body.rb#L43
Also, as for PoCPoC EnvironmentOS: macOS Monterey(12.3) Ruby ver: ruby 3.1.2p20 httparty ver: 0.20.0 (Python3 - HTTP Request Logging Server) PoC procedure(Linux or MacOS is required.
This is because Windows does not allow file names containing
I write Python code, but any method will work as long as you can see the HTTP Request Body. (e.g. Debugger, HTTP Logging Server, Packet Capture) $ vi logging.py
$ python logging.py
Return Request Header & Body:
Content-Disposition:
References
Golang https://github.com/golang/go/blob/e0e0c8fe9881bbbfe689ad94ca5dddbb252e4233/src/mime/multipart/writer.go#L144 Spring https://github.com/spring-projects/spring-framework/blob/4cc91e46b210b4e4e7ed182f93994511391b54ed/spring-web/src/main/java/org/springframework/http/ContentDisposition.java#L259-L267 Symphony https://github.com/symfony/symfony/blob/123b1651c4a7e219ba59074441badfac65525efe/src/Symfony/Component/Mime/Header/ParameterizedHeader.php#L128-L133 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
0.1.8
0.10.0
0.10.1
0.10.2
0.11.0
+ 67 more Show less
0.12.0
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.15.7
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.0
0.17.1
0.17.3
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.7.0
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
Fixed in
0.21.0
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.10.1
patch
2 CVEs
CVE-2025-68696
GHSA-hm5p-x4rq-38w4
Dec 23, 2025
httparty Has Potential SSRF Vulnerability That Leads to API Key Leakage
High
Network
Low
None
None
SummaryThere may be an SSRF vulnerability in httparty. This issue can pose a risk of leaking API keys, and it can also allow third parties to issue requests to internal servers. DetailsWhen httparty receives a path argument that is an absolute URL, it ignores the Consider the following example of a web application:
Now, suppose an attacker sends a request like this:
In this case, httparty sends the A similar problem was reported and fixed in the HTTP client library axios in the past: Also, Python's PoCFollow these steps to reproduce the issue:
Although Impact
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
0.1.8
0.10.0
0.10.1
0.10.2
0.11.0
+ 72 more Show less
0.12.0
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.15.7
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.0
0.17.1
0.17.3
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.7.0
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
Fixed in
0.24.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-22049
GHSA-5pq7-52mg-hr42
Jan 03, 2023
httparty has multipart/form-data request tampering vulnerability
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
ImpactI found "multipart/form-data request tampering vulnerability" caused by Content-Disposition "filename" lack of escaping in httparty.
https://github.com/jnunemaker/httparty/blob/4416141d37fd71bdba4f37589ec265f55aa446ce/lib/httparty/request/body.rb#L43 By exploiting this problem, the following attacks are possible
For example, this vulnerability can be exploited to generate the following Content-Disposition.
The Abused Header has multiple name ( These problems can result in successful or unsuccessful attacks, depending on the behavior of the parser receiving the request. I have confirmed that the attack succeeds, at least in the following frameworks
The cause of this problem is the lack of escaping of the WhatWG's HTML spec has an escaping requirement. https://html.spec.whatwg.org/#multipart-form-data
PatchesAs noted at the beginning of this section, encoding must be done as described in the HTML Spec. https://html.spec.whatwg.org/#multipart-form-data
Therefore, it is recommended that Content-Disposition be modified by either of the following
https://github.com/jnunemaker/httparty/blob/4416141d37fd71bdba4f37589ec265f55aa446ce/lib/httparty/request/body.rb#L43
Also, as for PoCPoC EnvironmentOS: macOS Monterey(12.3) Ruby ver: ruby 3.1.2p20 httparty ver: 0.20.0 (Python3 - HTTP Request Logging Server) PoC procedure(Linux or MacOS is required.
This is because Windows does not allow file names containing
I write Python code, but any method will work as long as you can see the HTTP Request Body. (e.g. Debugger, HTTP Logging Server, Packet Capture) $ vi logging.py
$ python logging.py
Return Request Header & Body:
Content-Disposition:
References
Golang https://github.com/golang/go/blob/e0e0c8fe9881bbbfe689ad94ca5dddbb252e4233/src/mime/multipart/writer.go#L144 Spring https://github.com/spring-projects/spring-framework/blob/4cc91e46b210b4e4e7ed182f93994511391b54ed/spring-web/src/main/java/org/springframework/http/ContentDisposition.java#L259-L267 Symphony https://github.com/symfony/symfony/blob/123b1651c4a7e219ba59074441badfac65525efe/src/Symfony/Component/Mime/Header/ParameterizedHeader.php#L128-L133 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
0.1.8
0.10.0
0.10.1
0.10.2
0.11.0
+ 67 more Show less
0.12.0
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.15.7
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.0
0.17.1
0.17.3
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.7.0
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
Fixed in
0.21.0
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.10.0
minor
2 CVEs
CVE-2025-68696
GHSA-hm5p-x4rq-38w4
Dec 23, 2025
httparty Has Potential SSRF Vulnerability That Leads to API Key Leakage
High
Network
Low
None
None
SummaryThere may be an SSRF vulnerability in httparty. This issue can pose a risk of leaking API keys, and it can also allow third parties to issue requests to internal servers. DetailsWhen httparty receives a path argument that is an absolute URL, it ignores the Consider the following example of a web application:
Now, suppose an attacker sends a request like this:
In this case, httparty sends the A similar problem was reported and fixed in the HTTP client library axios in the past: Also, Python's PoCFollow these steps to reproduce the issue:
Although Impact
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
0.1.8
0.10.0
0.10.1
0.10.2
0.11.0
+ 72 more Show less
0.12.0
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.15.7
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.0
0.17.1
0.17.3
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.7.0
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
Fixed in
0.24.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-22049
GHSA-5pq7-52mg-hr42
Jan 03, 2023
httparty has multipart/form-data request tampering vulnerability
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
ImpactI found "multipart/form-data request tampering vulnerability" caused by Content-Disposition "filename" lack of escaping in httparty.
https://github.com/jnunemaker/httparty/blob/4416141d37fd71bdba4f37589ec265f55aa446ce/lib/httparty/request/body.rb#L43 By exploiting this problem, the following attacks are possible
For example, this vulnerability can be exploited to generate the following Content-Disposition.
The Abused Header has multiple name ( These problems can result in successful or unsuccessful attacks, depending on the behavior of the parser receiving the request. I have confirmed that the attack succeeds, at least in the following frameworks
The cause of this problem is the lack of escaping of the WhatWG's HTML spec has an escaping requirement. https://html.spec.whatwg.org/#multipart-form-data
PatchesAs noted at the beginning of this section, encoding must be done as described in the HTML Spec. https://html.spec.whatwg.org/#multipart-form-data
Therefore, it is recommended that Content-Disposition be modified by either of the following
https://github.com/jnunemaker/httparty/blob/4416141d37fd71bdba4f37589ec265f55aa446ce/lib/httparty/request/body.rb#L43
Also, as for PoCPoC EnvironmentOS: macOS Monterey(12.3) Ruby ver: ruby 3.1.2p20 httparty ver: 0.20.0 (Python3 - HTTP Request Logging Server) PoC procedure(Linux or MacOS is required.
This is because Windows does not allow file names containing
I write Python code, but any method will work as long as you can see the HTTP Request Body. (e.g. Debugger, HTTP Logging Server, Packet Capture) $ vi logging.py
$ python logging.py
Return Request Header & Body:
Content-Disposition:
References
Golang https://github.com/golang/go/blob/e0e0c8fe9881bbbfe689ad94ca5dddbb252e4233/src/mime/multipart/writer.go#L144 Spring https://github.com/spring-projects/spring-framework/blob/4cc91e46b210b4e4e7ed182f93994511391b54ed/spring-web/src/main/java/org/springframework/http/ContentDisposition.java#L259-L267 Symphony https://github.com/symfony/symfony/blob/123b1651c4a7e219ba59074441badfac65525efe/src/Symfony/Component/Mime/Header/ParameterizedHeader.php#L128-L133 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
0.1.8
0.10.0
0.10.1
0.10.2
0.11.0
+ 67 more Show less
0.12.0
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.15.7
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.0
0.17.1
0.17.3
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.7.0
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
Fixed in
0.21.0
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.9.0
minor
3 CVEs
CVE-2025-68696
GHSA-hm5p-x4rq-38w4
Dec 23, 2025
httparty Has Potential SSRF Vulnerability That Leads to API Key Leakage
High
Network
Low
None
None
SummaryThere may be an SSRF vulnerability in httparty. This issue can pose a risk of leaking API keys, and it can also allow third parties to issue requests to internal servers. DetailsWhen httparty receives a path argument that is an absolute URL, it ignores the Consider the following example of a web application:
Now, suppose an attacker sends a request like this:
In this case, httparty sends the A similar problem was reported and fixed in the HTTP client library axios in the past: Also, Python's PoCFollow these steps to reproduce the issue:
Although Impact
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
0.1.8
0.10.0
0.10.1
0.10.2
0.11.0
+ 72 more Show less
0.12.0
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.15.7
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.0
0.17.1
0.17.3
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.7.0
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
Fixed in
0.24.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-22049
GHSA-5pq7-52mg-hr42
Jan 03, 2023
httparty has multipart/form-data request tampering vulnerability
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
ImpactI found "multipart/form-data request tampering vulnerability" caused by Content-Disposition "filename" lack of escaping in httparty.
https://github.com/jnunemaker/httparty/blob/4416141d37fd71bdba4f37589ec265f55aa446ce/lib/httparty/request/body.rb#L43 By exploiting this problem, the following attacks are possible
For example, this vulnerability can be exploited to generate the following Content-Disposition.
The Abused Header has multiple name ( These problems can result in successful or unsuccessful attacks, depending on the behavior of the parser receiving the request. I have confirmed that the attack succeeds, at least in the following frameworks
The cause of this problem is the lack of escaping of the WhatWG's HTML spec has an escaping requirement. https://html.spec.whatwg.org/#multipart-form-data
PatchesAs noted at the beginning of this section, encoding must be done as described in the HTML Spec. https://html.spec.whatwg.org/#multipart-form-data
Therefore, it is recommended that Content-Disposition be modified by either of the following
https://github.com/jnunemaker/httparty/blob/4416141d37fd71bdba4f37589ec265f55aa446ce/lib/httparty/request/body.rb#L43
Also, as for PoCPoC EnvironmentOS: macOS Monterey(12.3) Ruby ver: ruby 3.1.2p20 httparty ver: 0.20.0 (Python3 - HTTP Request Logging Server) PoC procedure(Linux or MacOS is required.
This is because Windows does not allow file names containing
I write Python code, but any method will work as long as you can see the HTTP Request Body. (e.g. Debugger, HTTP Logging Server, Packet Capture) $ vi logging.py
$ python logging.py
Return Request Header & Body:
Content-Disposition:
References
Golang https://github.com/golang/go/blob/e0e0c8fe9881bbbfe689ad94ca5dddbb252e4233/src/mime/multipart/writer.go#L144 Spring https://github.com/spring-projects/spring-framework/blob/4cc91e46b210b4e4e7ed182f93994511391b54ed/spring-web/src/main/java/org/springframework/http/ContentDisposition.java#L259-L267 Symphony https://github.com/symfony/symfony/blob/123b1651c4a7e219ba59074441badfac65525efe/src/Symfony/Component/Mime/Header/ParameterizedHeader.php#L128-L133 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
0.1.8
0.10.0
0.10.1
0.10.2
0.11.0
+ 67 more Show less
0.12.0
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.15.7
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.0
0.17.1
0.17.3
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.7.0
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
Fixed in
0.21.0
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2013-1801
GHSA-mgx3-27hr-mfgp
Oct 24, 2017
HTTParty does not restrict casts of string values
High
The httparty gem 0.9.0 and earlier for Ruby does not properly restrict casts of string values, which might allow remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU consumption) by leveraging Action Pack support for YAML type conversion, a similar vulnerability to CVE-2013-0156. Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.2.1
0.2.10
0.2.2
+ 32 more Show less
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.7.0
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
Fixed in
0.10.0
References
Updated Nov 29, 2024 · Source: OSV.dev | ||
0.8.3
patch
3 CVEs
CVE-2025-68696
GHSA-hm5p-x4rq-38w4
Dec 23, 2025
httparty Has Potential SSRF Vulnerability That Leads to API Key Leakage
High
Network
Low
None
None
SummaryThere may be an SSRF vulnerability in httparty. This issue can pose a risk of leaking API keys, and it can also allow third parties to issue requests to internal servers. DetailsWhen httparty receives a path argument that is an absolute URL, it ignores the Consider the following example of a web application:
Now, suppose an attacker sends a request like this:
In this case, httparty sends the A similar problem was reported and fixed in the HTTP client library axios in the past: Also, Python's PoCFollow these steps to reproduce the issue:
Although Impact
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
0.1.8
0.10.0
0.10.1
0.10.2
0.11.0
+ 72 more Show less
0.12.0
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.15.7
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.0
0.17.1
0.17.3
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.7.0
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
Fixed in
0.24.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-22049
GHSA-5pq7-52mg-hr42
Jan 03, 2023
httparty has multipart/form-data request tampering vulnerability
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
ImpactI found "multipart/form-data request tampering vulnerability" caused by Content-Disposition "filename" lack of escaping in httparty.
https://github.com/jnunemaker/httparty/blob/4416141d37fd71bdba4f37589ec265f55aa446ce/lib/httparty/request/body.rb#L43 By exploiting this problem, the following attacks are possible
For example, this vulnerability can be exploited to generate the following Content-Disposition.
The Abused Header has multiple name ( These problems can result in successful or unsuccessful attacks, depending on the behavior of the parser receiving the request. I have confirmed that the attack succeeds, at least in the following frameworks
The cause of this problem is the lack of escaping of the WhatWG's HTML spec has an escaping requirement. https://html.spec.whatwg.org/#multipart-form-data
PatchesAs noted at the beginning of this section, encoding must be done as described in the HTML Spec. https://html.spec.whatwg.org/#multipart-form-data
Therefore, it is recommended that Content-Disposition be modified by either of the following
https://github.com/jnunemaker/httparty/blob/4416141d37fd71bdba4f37589ec265f55aa446ce/lib/httparty/request/body.rb#L43
Also, as for PoCPoC EnvironmentOS: macOS Monterey(12.3) Ruby ver: ruby 3.1.2p20 httparty ver: 0.20.0 (Python3 - HTTP Request Logging Server) PoC procedure(Linux or MacOS is required.
This is because Windows does not allow file names containing
I write Python code, but any method will work as long as you can see the HTTP Request Body. (e.g. Debugger, HTTP Logging Server, Packet Capture) $ vi logging.py
$ python logging.py
Return Request Header & Body:
Content-Disposition:
References
Golang https://github.com/golang/go/blob/e0e0c8fe9881bbbfe689ad94ca5dddbb252e4233/src/mime/multipart/writer.go#L144 Spring https://github.com/spring-projects/spring-framework/blob/4cc91e46b210b4e4e7ed182f93994511391b54ed/spring-web/src/main/java/org/springframework/http/ContentDisposition.java#L259-L267 Symphony https://github.com/symfony/symfony/blob/123b1651c4a7e219ba59074441badfac65525efe/src/Symfony/Component/Mime/Header/ParameterizedHeader.php#L128-L133 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
0.1.8
0.10.0
0.10.1
0.10.2
0.11.0
+ 67 more Show less
0.12.0
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.15.7
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.0
0.17.1
0.17.3
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.7.0
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
Fixed in
0.21.0
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2013-1801
GHSA-mgx3-27hr-mfgp
Oct 24, 2017
HTTParty does not restrict casts of string values
High
The httparty gem 0.9.0 and earlier for Ruby does not properly restrict casts of string values, which might allow remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU consumption) by leveraging Action Pack support for YAML type conversion, a similar vulnerability to CVE-2013-0156. Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.2.1
0.2.10
0.2.2
+ 32 more Show less
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.7.0
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
Fixed in
0.10.0
References
Updated Nov 29, 2024 · Source: OSV.dev | ||
0.8.2
patch
3 CVEs
CVE-2025-68696
GHSA-hm5p-x4rq-38w4
Dec 23, 2025
httparty Has Potential SSRF Vulnerability That Leads to API Key Leakage
High
Network
Low
None
None
SummaryThere may be an SSRF vulnerability in httparty. This issue can pose a risk of leaking API keys, and it can also allow third parties to issue requests to internal servers. DetailsWhen httparty receives a path argument that is an absolute URL, it ignores the Consider the following example of a web application:
Now, suppose an attacker sends a request like this:
In this case, httparty sends the A similar problem was reported and fixed in the HTTP client library axios in the past: Also, Python's PoCFollow these steps to reproduce the issue:
Although Impact
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
0.1.8
0.10.0
0.10.1
0.10.2
0.11.0
+ 72 more Show less
0.12.0
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.15.7
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.0
0.17.1
0.17.3
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.7.0
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
Fixed in
0.24.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-22049
GHSA-5pq7-52mg-hr42
Jan 03, 2023
httparty has multipart/form-data request tampering vulnerability
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
ImpactI found "multipart/form-data request tampering vulnerability" caused by Content-Disposition "filename" lack of escaping in httparty.
https://github.com/jnunemaker/httparty/blob/4416141d37fd71bdba4f37589ec265f55aa446ce/lib/httparty/request/body.rb#L43 By exploiting this problem, the following attacks are possible
For example, this vulnerability can be exploited to generate the following Content-Disposition.
The Abused Header has multiple name ( These problems can result in successful or unsuccessful attacks, depending on the behavior of the parser receiving the request. I have confirmed that the attack succeeds, at least in the following frameworks
The cause of this problem is the lack of escaping of the WhatWG's HTML spec has an escaping requirement. https://html.spec.whatwg.org/#multipart-form-data
PatchesAs noted at the beginning of this section, encoding must be done as described in the HTML Spec. https://html.spec.whatwg.org/#multipart-form-data
Therefore, it is recommended that Content-Disposition be modified by either of the following
https://github.com/jnunemaker/httparty/blob/4416141d37fd71bdba4f37589ec265f55aa446ce/lib/httparty/request/body.rb#L43
Also, as for PoCPoC EnvironmentOS: macOS Monterey(12.3) Ruby ver: ruby 3.1.2p20 httparty ver: 0.20.0 (Python3 - HTTP Request Logging Server) PoC procedure(Linux or MacOS is required.
This is because Windows does not allow file names containing
I write Python code, but any method will work as long as you can see the HTTP Request Body. (e.g. Debugger, HTTP Logging Server, Packet Capture) $ vi logging.py
$ python logging.py
Return Request Header & Body:
Content-Disposition:
References
Golang https://github.com/golang/go/blob/e0e0c8fe9881bbbfe689ad94ca5dddbb252e4233/src/mime/multipart/writer.go#L144 Spring https://github.com/spring-projects/spring-framework/blob/4cc91e46b210b4e4e7ed182f93994511391b54ed/spring-web/src/main/java/org/springframework/http/ContentDisposition.java#L259-L267 Symphony https://github.com/symfony/symfony/blob/123b1651c4a7e219ba59074441badfac65525efe/src/Symfony/Component/Mime/Header/ParameterizedHeader.php#L128-L133 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
0.1.8
0.10.0
0.10.1
0.10.2
0.11.0
+ 67 more Show less
0.12.0
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.15.7
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.0
0.17.1
0.17.3
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.7.0
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
Fixed in
0.21.0
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2013-1801
GHSA-mgx3-27hr-mfgp
Oct 24, 2017
HTTParty does not restrict casts of string values
High
The httparty gem 0.9.0 and earlier for Ruby does not properly restrict casts of string values, which might allow remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU consumption) by leveraging Action Pack support for YAML type conversion, a similar vulnerability to CVE-2013-0156. Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.2.1
0.2.10
0.2.2
+ 32 more Show less
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.7.0
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
Fixed in
0.10.0
References
Updated Nov 29, 2024 · Source: OSV.dev | ||
0.8.1
patch
3 CVEs
CVE-2025-68696
GHSA-hm5p-x4rq-38w4
Dec 23, 2025
httparty Has Potential SSRF Vulnerability That Leads to API Key Leakage
High
Network
Low
None
None
SummaryThere may be an SSRF vulnerability in httparty. This issue can pose a risk of leaking API keys, and it can also allow third parties to issue requests to internal servers. DetailsWhen httparty receives a path argument that is an absolute URL, it ignores the Consider the following example of a web application:
Now, suppose an attacker sends a request like this:
In this case, httparty sends the A similar problem was reported and fixed in the HTTP client library axios in the past: Also, Python's PoCFollow these steps to reproduce the issue:
Although Impact
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
0.1.8
0.10.0
0.10.1
0.10.2
0.11.0
+ 72 more Show less
0.12.0
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.15.7
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.0
0.17.1
0.17.3
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.7.0
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
Fixed in
0.24.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-22049
GHSA-5pq7-52mg-hr42
Jan 03, 2023
httparty has multipart/form-data request tampering vulnerability
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
ImpactI found "multipart/form-data request tampering vulnerability" caused by Content-Disposition "filename" lack of escaping in httparty.
https://github.com/jnunemaker/httparty/blob/4416141d37fd71bdba4f37589ec265f55aa446ce/lib/httparty/request/body.rb#L43 By exploiting this problem, the following attacks are possible
For example, this vulnerability can be exploited to generate the following Content-Disposition.
The Abused Header has multiple name ( These problems can result in successful or unsuccessful attacks, depending on the behavior of the parser receiving the request. I have confirmed that the attack succeeds, at least in the following frameworks
The cause of this problem is the lack of escaping of the WhatWG's HTML spec has an escaping requirement. https://html.spec.whatwg.org/#multipart-form-data
PatchesAs noted at the beginning of this section, encoding must be done as described in the HTML Spec. https://html.spec.whatwg.org/#multipart-form-data
Therefore, it is recommended that Content-Disposition be modified by either of the following
https://github.com/jnunemaker/httparty/blob/4416141d37fd71bdba4f37589ec265f55aa446ce/lib/httparty/request/body.rb#L43
Also, as for PoCPoC EnvironmentOS: macOS Monterey(12.3) Ruby ver: ruby 3.1.2p20 httparty ver: 0.20.0 (Python3 - HTTP Request Logging Server) PoC procedure(Linux or MacOS is required.
This is because Windows does not allow file names containing
I write Python code, but any method will work as long as you can see the HTTP Request Body. (e.g. Debugger, HTTP Logging Server, Packet Capture) $ vi logging.py
$ python logging.py
Return Request Header & Body:
Content-Disposition:
References
Golang https://github.com/golang/go/blob/e0e0c8fe9881bbbfe689ad94ca5dddbb252e4233/src/mime/multipart/writer.go#L144 Spring https://github.com/spring-projects/spring-framework/blob/4cc91e46b210b4e4e7ed182f93994511391b54ed/spring-web/src/main/java/org/springframework/http/ContentDisposition.java#L259-L267 Symphony https://github.com/symfony/symfony/blob/123b1651c4a7e219ba59074441badfac65525efe/src/Symfony/Component/Mime/Header/ParameterizedHeader.php#L128-L133 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
0.1.8
0.10.0
0.10.1
0.10.2
0.11.0
+ 67 more Show less
0.12.0
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.15.7
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.0
0.17.1
0.17.3
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.7.0
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
Fixed in
0.21.0
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2013-1801
GHSA-mgx3-27hr-mfgp
Oct 24, 2017
HTTParty does not restrict casts of string values
High
The httparty gem 0.9.0 and earlier for Ruby does not properly restrict casts of string values, which might allow remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU consumption) by leveraging Action Pack support for YAML type conversion, a similar vulnerability to CVE-2013-0156. Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.2.1
0.2.10
0.2.2
+ 32 more Show less
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.7.0
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
Fixed in
0.10.0
References
Updated Nov 29, 2024 · Source: OSV.dev | ||
0.8.0
minor
3 CVEs
CVE-2025-68696
GHSA-hm5p-x4rq-38w4
Dec 23, 2025
httparty Has Potential SSRF Vulnerability That Leads to API Key Leakage
High
Network
Low
None
None
SummaryThere may be an SSRF vulnerability in httparty. This issue can pose a risk of leaking API keys, and it can also allow third parties to issue requests to internal servers. DetailsWhen httparty receives a path argument that is an absolute URL, it ignores the Consider the following example of a web application:
Now, suppose an attacker sends a request like this:
In this case, httparty sends the A similar problem was reported and fixed in the HTTP client library axios in the past: Also, Python's PoCFollow these steps to reproduce the issue:
Although Impact
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
0.1.8
0.10.0
0.10.1
0.10.2
0.11.0
+ 72 more Show less
0.12.0
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.15.7
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.0
0.17.1
0.17.3
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.7.0
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
Fixed in
0.24.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-22049
GHSA-5pq7-52mg-hr42
Jan 03, 2023
httparty has multipart/form-data request tampering vulnerability
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
ImpactI found "multipart/form-data request tampering vulnerability" caused by Content-Disposition "filename" lack of escaping in httparty.
https://github.com/jnunemaker/httparty/blob/4416141d37fd71bdba4f37589ec265f55aa446ce/lib/httparty/request/body.rb#L43 By exploiting this problem, the following attacks are possible
For example, this vulnerability can be exploited to generate the following Content-Disposition.
The Abused Header has multiple name ( These problems can result in successful or unsuccessful attacks, depending on the behavior of the parser receiving the request. I have confirmed that the attack succeeds, at least in the following frameworks
The cause of this problem is the lack of escaping of the WhatWG's HTML spec has an escaping requirement. https://html.spec.whatwg.org/#multipart-form-data
PatchesAs noted at the beginning of this section, encoding must be done as described in the HTML Spec. https://html.spec.whatwg.org/#multipart-form-data
Therefore, it is recommended that Content-Disposition be modified by either of the following
https://github.com/jnunemaker/httparty/blob/4416141d37fd71bdba4f37589ec265f55aa446ce/lib/httparty/request/body.rb#L43
Also, as for PoCPoC EnvironmentOS: macOS Monterey(12.3) Ruby ver: ruby 3.1.2p20 httparty ver: 0.20.0 (Python3 - HTTP Request Logging Server) PoC procedure(Linux or MacOS is required.
This is because Windows does not allow file names containing
I write Python code, but any method will work as long as you can see the HTTP Request Body. (e.g. Debugger, HTTP Logging Server, Packet Capture) $ vi logging.py
$ python logging.py
Return Request Header & Body:
Content-Disposition:
References
Golang https://github.com/golang/go/blob/e0e0c8fe9881bbbfe689ad94ca5dddbb252e4233/src/mime/multipart/writer.go#L144 Spring https://github.com/spring-projects/spring-framework/blob/4cc91e46b210b4e4e7ed182f93994511391b54ed/spring-web/src/main/java/org/springframework/http/ContentDisposition.java#L259-L267 Symphony https://github.com/symfony/symfony/blob/123b1651c4a7e219ba59074441badfac65525efe/src/Symfony/Component/Mime/Header/ParameterizedHeader.php#L128-L133 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
0.1.8
0.10.0
0.10.1
0.10.2
0.11.0
+ 67 more Show less
0.12.0
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.15.7
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.0
0.17.1
0.17.3
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.7.0
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
Fixed in
0.21.0
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2013-1801
GHSA-mgx3-27hr-mfgp
Oct 24, 2017
HTTParty does not restrict casts of string values
High
The httparty gem 0.9.0 and earlier for Ruby does not properly restrict casts of string values, which might allow remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU consumption) by leveraging Action Pack support for YAML type conversion, a similar vulnerability to CVE-2013-0156. Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.2.1
0.2.10
0.2.2
+ 32 more Show less
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.7.0
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
Fixed in
0.10.0
References
Updated Nov 29, 2024 · Source: OSV.dev | ||
0.7.8
patch
3 CVEs
CVE-2025-68696
GHSA-hm5p-x4rq-38w4
Dec 23, 2025
httparty Has Potential SSRF Vulnerability That Leads to API Key Leakage
High
Network
Low
None
None
SummaryThere may be an SSRF vulnerability in httparty. This issue can pose a risk of leaking API keys, and it can also allow third parties to issue requests to internal servers. DetailsWhen httparty receives a path argument that is an absolute URL, it ignores the Consider the following example of a web application:
Now, suppose an attacker sends a request like this:
In this case, httparty sends the A similar problem was reported and fixed in the HTTP client library axios in the past: Also, Python's PoCFollow these steps to reproduce the issue:
Although Impact
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
0.1.8
0.10.0
0.10.1
0.10.2
0.11.0
+ 72 more Show less
0.12.0
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.15.7
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.0
0.17.1
0.17.3
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.7.0
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
Fixed in
0.24.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-22049
GHSA-5pq7-52mg-hr42
Jan 03, 2023
httparty has multipart/form-data request tampering vulnerability
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
ImpactI found "multipart/form-data request tampering vulnerability" caused by Content-Disposition "filename" lack of escaping in httparty.
https://github.com/jnunemaker/httparty/blob/4416141d37fd71bdba4f37589ec265f55aa446ce/lib/httparty/request/body.rb#L43 By exploiting this problem, the following attacks are possible
For example, this vulnerability can be exploited to generate the following Content-Disposition.
The Abused Header has multiple name ( These problems can result in successful or unsuccessful attacks, depending on the behavior of the parser receiving the request. I have confirmed that the attack succeeds, at least in the following frameworks
The cause of this problem is the lack of escaping of the WhatWG's HTML spec has an escaping requirement. https://html.spec.whatwg.org/#multipart-form-data
PatchesAs noted at the beginning of this section, encoding must be done as described in the HTML Spec. https://html.spec.whatwg.org/#multipart-form-data
Therefore, it is recommended that Content-Disposition be modified by either of the following
https://github.com/jnunemaker/httparty/blob/4416141d37fd71bdba4f37589ec265f55aa446ce/lib/httparty/request/body.rb#L43
Also, as for PoCPoC EnvironmentOS: macOS Monterey(12.3) Ruby ver: ruby 3.1.2p20 httparty ver: 0.20.0 (Python3 - HTTP Request Logging Server) PoC procedure(Linux or MacOS is required.
This is because Windows does not allow file names containing
I write Python code, but any method will work as long as you can see the HTTP Request Body. (e.g. Debugger, HTTP Logging Server, Packet Capture) $ vi logging.py
$ python logging.py
Return Request Header & Body:
Content-Disposition:
References
Golang https://github.com/golang/go/blob/e0e0c8fe9881bbbfe689ad94ca5dddbb252e4233/src/mime/multipart/writer.go#L144 Spring https://github.com/spring-projects/spring-framework/blob/4cc91e46b210b4e4e7ed182f93994511391b54ed/spring-web/src/main/java/org/springframework/http/ContentDisposition.java#L259-L267 Symphony https://github.com/symfony/symfony/blob/123b1651c4a7e219ba59074441badfac65525efe/src/Symfony/Component/Mime/Header/ParameterizedHeader.php#L128-L133 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
0.1.8
0.10.0
0.10.1
0.10.2
0.11.0
+ 67 more Show less
0.12.0
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.15.7
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.0
0.17.1
0.17.3
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.7.0
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
Fixed in
0.21.0
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2013-1801
GHSA-mgx3-27hr-mfgp
Oct 24, 2017
HTTParty does not restrict casts of string values
High
The httparty gem 0.9.0 and earlier for Ruby does not properly restrict casts of string values, which might allow remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU consumption) by leveraging Action Pack support for YAML type conversion, a similar vulnerability to CVE-2013-0156. Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.2.1
0.2.10
0.2.2
+ 32 more Show less
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.7.0
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
Fixed in
0.10.0
References
Updated Nov 29, 2024 · Source: OSV.dev | ||
0.7.7
patch
3 CVEs
CVE-2025-68696
GHSA-hm5p-x4rq-38w4
Dec 23, 2025
httparty Has Potential SSRF Vulnerability That Leads to API Key Leakage
High
Network
Low
None
None
SummaryThere may be an SSRF vulnerability in httparty. This issue can pose a risk of leaking API keys, and it can also allow third parties to issue requests to internal servers. DetailsWhen httparty receives a path argument that is an absolute URL, it ignores the Consider the following example of a web application:
Now, suppose an attacker sends a request like this:
In this case, httparty sends the A similar problem was reported and fixed in the HTTP client library axios in the past: Also, Python's PoCFollow these steps to reproduce the issue:
Although Impact
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
0.1.8
0.10.0
0.10.1
0.10.2
0.11.0
+ 72 more Show less
0.12.0
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.15.7
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.0
0.17.1
0.17.3
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.21.0
0.22.0
0.23.0
0.23.1
0.23.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.7.0
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
Fixed in
0.24.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-22049
GHSA-5pq7-52mg-hr42
Jan 03, 2023
httparty has multipart/form-data request tampering vulnerability
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
ImpactI found "multipart/form-data request tampering vulnerability" caused by Content-Disposition "filename" lack of escaping in httparty.
https://github.com/jnunemaker/httparty/blob/4416141d37fd71bdba4f37589ec265f55aa446ce/lib/httparty/request/body.rb#L43 By exploiting this problem, the following attacks are possible
For example, this vulnerability can be exploited to generate the following Content-Disposition.
The Abused Header has multiple name ( These problems can result in successful or unsuccessful attacks, depending on the behavior of the parser receiving the request. I have confirmed that the attack succeeds, at least in the following frameworks
The cause of this problem is the lack of escaping of the WhatWG's HTML spec has an escaping requirement. https://html.spec.whatwg.org/#multipart-form-data
PatchesAs noted at the beginning of this section, encoding must be done as described in the HTML Spec. https://html.spec.whatwg.org/#multipart-form-data
Therefore, it is recommended that Content-Disposition be modified by either of the following
https://github.com/jnunemaker/httparty/blob/4416141d37fd71bdba4f37589ec265f55aa446ce/lib/httparty/request/body.rb#L43
Also, as for PoCPoC EnvironmentOS: macOS Monterey(12.3) Ruby ver: ruby 3.1.2p20 httparty ver: 0.20.0 (Python3 - HTTP Request Logging Server) PoC procedure(Linux or MacOS is required.
This is because Windows does not allow file names containing
I write Python code, but any method will work as long as you can see the HTTP Request Body. (e.g. Debugger, HTTP Logging Server, Packet Capture) $ vi logging.py
$ python logging.py
Return Request Header & Body:
Content-Disposition:
References
Golang https://github.com/golang/go/blob/e0e0c8fe9881bbbfe689ad94ca5dddbb252e4233/src/mime/multipart/writer.go#L144 Spring https://github.com/spring-projects/spring-framework/blob/4cc91e46b210b4e4e7ed182f93994511391b54ed/spring-web/src/main/java/org/springframework/http/ContentDisposition.java#L259-L267 Symphony https://github.com/symfony/symfony/blob/123b1651c4a7e219ba59074441badfac65525efe/src/Symfony/Component/Mime/Header/ParameterizedHeader.php#L128-L133 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
0.1.8
0.10.0
0.10.1
0.10.2
0.11.0
+ 67 more Show less
0.12.0
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.15.0
0.15.1
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.15.7
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.0
0.17.1
0.17.3
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.7.0
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
Fixed in
0.21.0
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2013-1801
GHSA-mgx3-27hr-mfgp
Oct 24, 2017
HTTParty does not restrict casts of string values
High
The httparty gem 0.9.0 and earlier for Ruby does not properly restrict casts of string values, which might allow remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU consumption) by leveraging Action Pack support for YAML type conversion, a similar vulnerability to CVE-2013-0156. Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.2.1
0.2.10
0.2.2
+ 32 more Show less
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.7.0
0.7.2
0.7.3
0.7.4
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
Fixed in
0.10.0
References
Updated Nov 29, 2024 · Source: OSV.dev |