uri
URI is a module providing classes to handle Uniform Resource Identifiers
Activity
- Latest release
- 10mo ago
- Total releases
- 28
- Cadence
- ~daily
- Last 12 months
- 5
Reach
- Stars
- —
Details
- License
- unknown OR BSD-2-Clause
- First release
- Apr 01, 2020
| Version | Released | |
|---|---|---|
1.1.1
patch
| ||
1.1.0
minor
| ||
1.0.4
patch
| ||
0.13.3
patch
| ||
0.12.5
patch
| ||
0.11.3
patch
1 CVE
CVE-2025-61594
GHSA-j4pr-3wm6-xx2r
Dec 30, 2025
URI Credential Leakage Bypass over CVE-2025-27221
Low
Network
Low
None
None
ImpactIn affected URI version, a bypass exists for the fix to CVE-2025-27221 that can expose user credentials. When using the The vulnerability affects the
PatchesUpgrade to 0.12.5, 0.13.3 or 1.0.4 References
Affected versions
0.10.0
0.10.0.1
0.10.0.2
0.10.0.3
0.10.1
0.10.2
0.10.3
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
+ 11 more Show less
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.13.2
1.0.0
1.0.1
1.0.2
1.0.3
Fixed in
0.12.5
0.13.3
1.0.4
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.13.2
patch
1 CVE
CVE-2025-61594
GHSA-j4pr-3wm6-xx2r
Dec 30, 2025
URI Credential Leakage Bypass over CVE-2025-27221
Low
Network
Low
None
None
ImpactIn affected URI version, a bypass exists for the fix to CVE-2025-27221 that can expose user credentials. When using the The vulnerability affects the
PatchesUpgrade to 0.12.5, 0.13.3 or 1.0.4 References
Affected versions
0.10.0
0.10.0.1
0.10.0.2
0.10.0.3
0.10.1
0.10.2
0.10.3
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
+ 11 more Show less
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.13.2
1.0.0
1.0.1
1.0.2
1.0.3
Fixed in
0.12.5
0.13.3
1.0.4
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.12.4
patch
1 CVE
CVE-2025-61594
GHSA-j4pr-3wm6-xx2r
Dec 30, 2025
URI Credential Leakage Bypass over CVE-2025-27221
Low
Network
Low
None
None
ImpactIn affected URI version, a bypass exists for the fix to CVE-2025-27221 that can expose user credentials. When using the The vulnerability affects the
PatchesUpgrade to 0.12.5, 0.13.3 or 1.0.4 References
Affected versions
0.10.0
0.10.0.1
0.10.0.2
0.10.0.3
0.10.1
0.10.2
0.10.3
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
+ 11 more Show less
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.13.2
1.0.0
1.0.1
1.0.2
1.0.3
Fixed in
0.12.5
0.13.3
1.0.4
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.0.3
patch
1 CVE
CVE-2025-61594
GHSA-j4pr-3wm6-xx2r
Dec 30, 2025
URI Credential Leakage Bypass over CVE-2025-27221
Low
Network
Low
None
None
ImpactIn affected URI version, a bypass exists for the fix to CVE-2025-27221 that can expose user credentials. When using the The vulnerability affects the
PatchesUpgrade to 0.12.5, 0.13.3 or 1.0.4 References
Affected versions
0.10.0
0.10.0.1
0.10.0.2
0.10.0.3
0.10.1
0.10.2
0.10.3
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
+ 11 more Show less
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.13.2
1.0.0
1.0.1
1.0.2
1.0.3
Fixed in
0.12.5
0.13.3
1.0.4
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.0.2
patch
2 CVEs
CVE-2025-61594
GHSA-j4pr-3wm6-xx2r
Dec 30, 2025
URI Credential Leakage Bypass over CVE-2025-27221
Low
Network
Low
None
None
ImpactIn affected URI version, a bypass exists for the fix to CVE-2025-27221 that can expose user credentials. When using the The vulnerability affects the
PatchesUpgrade to 0.12.5, 0.13.3 or 1.0.4 References
Affected versions
0.10.0
0.10.0.1
0.10.0.2
0.10.0.3
0.10.1
0.10.2
0.10.3
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
+ 11 more Show less
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.13.2
1.0.0
1.0.1
1.0.2
1.0.3
Fixed in
0.12.5
0.13.3
1.0.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-27221
GHSA-22h5-pq3x-2gf2
Mar 03, 2025
URI allows for userinfo Leakage in URI#join, URI#merge, and URI#+
Low
Local
Low
None
None
There is a possibility for userinfo leakage by in the uri gem. This vulnerability has been assigned the CVE identifier CVE-2025-27221. We recommend upgrading the uri gem. DetailsThe methods Please update URI gem to version 0.11.3, 0.12.4, 0.13.2, 1.0.3 or later. Affected versionsuri gem versions < 0.11.3, 0.12.0 to 0.12.3, 0.13.0, 0.13.1 and 1.0.0 to 1.0.2. CreditsThanks to Tsubasa Irisawa (lambdasawa) for discovering this issue. Also thanks to nobu for additional fixes of this vulnerability. Affected versions
0.10.0
0.10.0.1
0.10.0.2
0.10.0.3
0.10.1
0.10.2
0.10.3
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
+ 7 more Show less
0.12.2
0.12.3
0.13.0
0.13.1
1.0.0
1.0.1
1.0.2
Fixed in
0.11.3
0.12.4
0.13.2
1.0.3
References Updated Sep 10, 2026 · Source: OSV.dev | ||
1.0.1
patch
2 CVEs
CVE-2025-61594
GHSA-j4pr-3wm6-xx2r
Dec 30, 2025
URI Credential Leakage Bypass over CVE-2025-27221
Low
Network
Low
None
None
ImpactIn affected URI version, a bypass exists for the fix to CVE-2025-27221 that can expose user credentials. When using the The vulnerability affects the
PatchesUpgrade to 0.12.5, 0.13.3 or 1.0.4 References
Affected versions
0.10.0
0.10.0.1
0.10.0.2
0.10.0.3
0.10.1
0.10.2
0.10.3
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
+ 11 more Show less
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.13.2
1.0.0
1.0.1
1.0.2
1.0.3
Fixed in
0.12.5
0.13.3
1.0.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-27221
GHSA-22h5-pq3x-2gf2
Mar 03, 2025
URI allows for userinfo Leakage in URI#join, URI#merge, and URI#+
Low
Local
Low
None
None
There is a possibility for userinfo leakage by in the uri gem. This vulnerability has been assigned the CVE identifier CVE-2025-27221. We recommend upgrading the uri gem. DetailsThe methods Please update URI gem to version 0.11.3, 0.12.4, 0.13.2, 1.0.3 or later. Affected versionsuri gem versions < 0.11.3, 0.12.0 to 0.12.3, 0.13.0, 0.13.1 and 1.0.0 to 1.0.2. CreditsThanks to Tsubasa Irisawa (lambdasawa) for discovering this issue. Also thanks to nobu for additional fixes of this vulnerability. Affected versions
0.10.0
0.10.0.1
0.10.0.2
0.10.0.3
0.10.1
0.10.2
0.10.3
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
+ 7 more Show less
0.12.2
0.12.3
0.13.0
0.13.1
1.0.0
1.0.1
1.0.2
Fixed in
0.11.3
0.12.4
0.13.2
1.0.3
References Updated Sep 10, 2026 · Source: OSV.dev | ||
1.0.0
major
2 CVEs
CVE-2025-61594
GHSA-j4pr-3wm6-xx2r
Dec 30, 2025
URI Credential Leakage Bypass over CVE-2025-27221
Low
Network
Low
None
None
ImpactIn affected URI version, a bypass exists for the fix to CVE-2025-27221 that can expose user credentials. When using the The vulnerability affects the
PatchesUpgrade to 0.12.5, 0.13.3 or 1.0.4 References
Affected versions
0.10.0
0.10.0.1
0.10.0.2
0.10.0.3
0.10.1
0.10.2
0.10.3
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
+ 11 more Show less
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.13.2
1.0.0
1.0.1
1.0.2
1.0.3
Fixed in
0.12.5
0.13.3
1.0.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-27221
GHSA-22h5-pq3x-2gf2
Mar 03, 2025
URI allows for userinfo Leakage in URI#join, URI#merge, and URI#+
Low
Local
Low
None
None
There is a possibility for userinfo leakage by in the uri gem. This vulnerability has been assigned the CVE identifier CVE-2025-27221. We recommend upgrading the uri gem. DetailsThe methods Please update URI gem to version 0.11.3, 0.12.4, 0.13.2, 1.0.3 or later. Affected versionsuri gem versions < 0.11.3, 0.12.0 to 0.12.3, 0.13.0, 0.13.1 and 1.0.0 to 1.0.2. CreditsThanks to Tsubasa Irisawa (lambdasawa) for discovering this issue. Also thanks to nobu for additional fixes of this vulnerability. Affected versions
0.10.0
0.10.0.1
0.10.0.2
0.10.0.3
0.10.1
0.10.2
0.10.3
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
+ 7 more Show less
0.12.2
0.12.3
0.13.0
0.13.1
1.0.0
1.0.1
1.0.2
Fixed in
0.11.3
0.12.4
0.13.2
1.0.3
References Updated Sep 10, 2026 · Source: OSV.dev | ||
0.13.1
patch
2 CVEs
CVE-2025-61594
GHSA-j4pr-3wm6-xx2r
Dec 30, 2025
URI Credential Leakage Bypass over CVE-2025-27221
Low
Network
Low
None
None
ImpactIn affected URI version, a bypass exists for the fix to CVE-2025-27221 that can expose user credentials. When using the The vulnerability affects the
PatchesUpgrade to 0.12.5, 0.13.3 or 1.0.4 References
Affected versions
0.10.0
0.10.0.1
0.10.0.2
0.10.0.3
0.10.1
0.10.2
0.10.3
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
+ 11 more Show less
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.13.2
1.0.0
1.0.1
1.0.2
1.0.3
Fixed in
0.12.5
0.13.3
1.0.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-27221
GHSA-22h5-pq3x-2gf2
Mar 03, 2025
URI allows for userinfo Leakage in URI#join, URI#merge, and URI#+
Low
Local
Low
None
None
There is a possibility for userinfo leakage by in the uri gem. This vulnerability has been assigned the CVE identifier CVE-2025-27221. We recommend upgrading the uri gem. DetailsThe methods Please update URI gem to version 0.11.3, 0.12.4, 0.13.2, 1.0.3 or later. Affected versionsuri gem versions < 0.11.3, 0.12.0 to 0.12.3, 0.13.0, 0.13.1 and 1.0.0 to 1.0.2. CreditsThanks to Tsubasa Irisawa (lambdasawa) for discovering this issue. Also thanks to nobu for additional fixes of this vulnerability. Affected versions
0.10.0
0.10.0.1
0.10.0.2
0.10.0.3
0.10.1
0.10.2
0.10.3
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
+ 7 more Show less
0.12.2
0.12.3
0.13.0
0.13.1
1.0.0
1.0.1
1.0.2
Fixed in
0.11.3
0.12.4
0.13.2
1.0.3
References Updated Sep 10, 2026 · Source: OSV.dev | ||
0.12.3
patch
2 CVEs
CVE-2025-61594
GHSA-j4pr-3wm6-xx2r
Dec 30, 2025
URI Credential Leakage Bypass over CVE-2025-27221
Low
Network
Low
None
None
ImpactIn affected URI version, a bypass exists for the fix to CVE-2025-27221 that can expose user credentials. When using the The vulnerability affects the
PatchesUpgrade to 0.12.5, 0.13.3 or 1.0.4 References
Affected versions
0.10.0
0.10.0.1
0.10.0.2
0.10.0.3
0.10.1
0.10.2
0.10.3
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
+ 11 more Show less
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.13.2
1.0.0
1.0.1
1.0.2
1.0.3
Fixed in
0.12.5
0.13.3
1.0.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-27221
GHSA-22h5-pq3x-2gf2
Mar 03, 2025
URI allows for userinfo Leakage in URI#join, URI#merge, and URI#+
Low
Local
Low
None
None
There is a possibility for userinfo leakage by in the uri gem. This vulnerability has been assigned the CVE identifier CVE-2025-27221. We recommend upgrading the uri gem. DetailsThe methods Please update URI gem to version 0.11.3, 0.12.4, 0.13.2, 1.0.3 or later. Affected versionsuri gem versions < 0.11.3, 0.12.0 to 0.12.3, 0.13.0, 0.13.1 and 1.0.0 to 1.0.2. CreditsThanks to Tsubasa Irisawa (lambdasawa) for discovering this issue. Also thanks to nobu for additional fixes of this vulnerability. Affected versions
0.10.0
0.10.0.1
0.10.0.2
0.10.0.3
0.10.1
0.10.2
0.10.3
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
+ 7 more Show less
0.12.2
0.12.3
0.13.0
0.13.1
1.0.0
1.0.1
1.0.2
Fixed in
0.11.3
0.12.4
0.13.2
1.0.3
References Updated Sep 10, 2026 · Source: OSV.dev | ||
0.13.0
minor
2 CVEs
CVE-2025-61594
GHSA-j4pr-3wm6-xx2r
Dec 30, 2025
URI Credential Leakage Bypass over CVE-2025-27221
Low
Network
Low
None
None
ImpactIn affected URI version, a bypass exists for the fix to CVE-2025-27221 that can expose user credentials. When using the The vulnerability affects the
PatchesUpgrade to 0.12.5, 0.13.3 or 1.0.4 References
Affected versions
0.10.0
0.10.0.1
0.10.0.2
0.10.0.3
0.10.1
0.10.2
0.10.3
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
+ 11 more Show less
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.13.2
1.0.0
1.0.1
1.0.2
1.0.3
Fixed in
0.12.5
0.13.3
1.0.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-27221
GHSA-22h5-pq3x-2gf2
Mar 03, 2025
URI allows for userinfo Leakage in URI#join, URI#merge, and URI#+
Low
Local
Low
None
None
There is a possibility for userinfo leakage by in the uri gem. This vulnerability has been assigned the CVE identifier CVE-2025-27221. We recommend upgrading the uri gem. DetailsThe methods Please update URI gem to version 0.11.3, 0.12.4, 0.13.2, 1.0.3 or later. Affected versionsuri gem versions < 0.11.3, 0.12.0 to 0.12.3, 0.13.0, 0.13.1 and 1.0.0 to 1.0.2. CreditsThanks to Tsubasa Irisawa (lambdasawa) for discovering this issue. Also thanks to nobu for additional fixes of this vulnerability. Affected versions
0.10.0
0.10.0.1
0.10.0.2
0.10.0.3
0.10.1
0.10.2
0.10.3
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
+ 7 more Show less
0.12.2
0.12.3
0.13.0
0.13.1
1.0.0
1.0.1
1.0.2
Fixed in
0.11.3
0.12.4
0.13.2
1.0.3
References Updated Sep 10, 2026 · Source: OSV.dev | ||
0.10.3
patch
2 CVEs
CVE-2025-61594
GHSA-j4pr-3wm6-xx2r
Dec 30, 2025
URI Credential Leakage Bypass over CVE-2025-27221
Low
Network
Low
None
None
ImpactIn affected URI version, a bypass exists for the fix to CVE-2025-27221 that can expose user credentials. When using the The vulnerability affects the
PatchesUpgrade to 0.12.5, 0.13.3 or 1.0.4 References
Affected versions
0.10.0
0.10.0.1
0.10.0.2
0.10.0.3
0.10.1
0.10.2
0.10.3
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
+ 11 more Show less
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.13.2
1.0.0
1.0.1
1.0.2
1.0.3
Fixed in
0.12.5
0.13.3
1.0.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-27221
GHSA-22h5-pq3x-2gf2
Mar 03, 2025
URI allows for userinfo Leakage in URI#join, URI#merge, and URI#+
Low
Local
Low
None
None
There is a possibility for userinfo leakage by in the uri gem. This vulnerability has been assigned the CVE identifier CVE-2025-27221. We recommend upgrading the uri gem. DetailsThe methods Please update URI gem to version 0.11.3, 0.12.4, 0.13.2, 1.0.3 or later. Affected versionsuri gem versions < 0.11.3, 0.12.0 to 0.12.3, 0.13.0, 0.13.1 and 1.0.0 to 1.0.2. CreditsThanks to Tsubasa Irisawa (lambdasawa) for discovering this issue. Also thanks to nobu for additional fixes of this vulnerability. Affected versions
0.10.0
0.10.0.1
0.10.0.2
0.10.0.3
0.10.1
0.10.2
0.10.3
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
+ 7 more Show less
0.12.2
0.12.3
0.13.0
0.13.1
1.0.0
1.0.1
1.0.2
Fixed in
0.11.3
0.12.4
0.13.2
1.0.3
References Updated Sep 10, 2026 · Source: OSV.dev | ||
0.11.2
patch
2 CVEs
CVE-2025-61594
GHSA-j4pr-3wm6-xx2r
Dec 30, 2025
URI Credential Leakage Bypass over CVE-2025-27221
Low
Network
Low
None
None
ImpactIn affected URI version, a bypass exists for the fix to CVE-2025-27221 that can expose user credentials. When using the The vulnerability affects the
PatchesUpgrade to 0.12.5, 0.13.3 or 1.0.4 References
Affected versions
0.10.0
0.10.0.1
0.10.0.2
0.10.0.3
0.10.1
0.10.2
0.10.3
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
+ 11 more Show less
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.13.2
1.0.0
1.0.1
1.0.2
1.0.3
Fixed in
0.12.5
0.13.3
1.0.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-27221
GHSA-22h5-pq3x-2gf2
Mar 03, 2025
URI allows for userinfo Leakage in URI#join, URI#merge, and URI#+
Low
Local
Low
None
None
There is a possibility for userinfo leakage by in the uri gem. This vulnerability has been assigned the CVE identifier CVE-2025-27221. We recommend upgrading the uri gem. DetailsThe methods Please update URI gem to version 0.11.3, 0.12.4, 0.13.2, 1.0.3 or later. Affected versionsuri gem versions < 0.11.3, 0.12.0 to 0.12.3, 0.13.0, 0.13.1 and 1.0.0 to 1.0.2. CreditsThanks to Tsubasa Irisawa (lambdasawa) for discovering this issue. Also thanks to nobu for additional fixes of this vulnerability. Affected versions
0.10.0
0.10.0.1
0.10.0.2
0.10.0.3
0.10.1
0.10.2
0.10.3
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
+ 7 more Show less
0.12.2
0.12.3
0.13.0
0.13.1
1.0.0
1.0.1
1.0.2
Fixed in
0.11.3
0.12.4
0.13.2
1.0.3
References Updated Sep 10, 2026 · Source: OSV.dev | ||
0.12.2
patch
2 CVEs
CVE-2025-61594
GHSA-j4pr-3wm6-xx2r
Dec 30, 2025
URI Credential Leakage Bypass over CVE-2025-27221
Low
Network
Low
None
None
ImpactIn affected URI version, a bypass exists for the fix to CVE-2025-27221 that can expose user credentials. When using the The vulnerability affects the
PatchesUpgrade to 0.12.5, 0.13.3 or 1.0.4 References
Affected versions
0.10.0
0.10.0.1
0.10.0.2
0.10.0.3
0.10.1
0.10.2
0.10.3
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
+ 11 more Show less
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.13.2
1.0.0
1.0.1
1.0.2
1.0.3
Fixed in
0.12.5
0.13.3
1.0.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-27221
GHSA-22h5-pq3x-2gf2
Mar 03, 2025
URI allows for userinfo Leakage in URI#join, URI#merge, and URI#+
Low
Local
Low
None
None
There is a possibility for userinfo leakage by in the uri gem. This vulnerability has been assigned the CVE identifier CVE-2025-27221. We recommend upgrading the uri gem. DetailsThe methods Please update URI gem to version 0.11.3, 0.12.4, 0.13.2, 1.0.3 or later. Affected versionsuri gem versions < 0.11.3, 0.12.0 to 0.12.3, 0.13.0, 0.13.1 and 1.0.0 to 1.0.2. CreditsThanks to Tsubasa Irisawa (lambdasawa) for discovering this issue. Also thanks to nobu for additional fixes of this vulnerability. Affected versions
0.10.0
0.10.0.1
0.10.0.2
0.10.0.3
0.10.1
0.10.2
0.10.3
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
+ 7 more Show less
0.12.2
0.12.3
0.13.0
0.13.1
1.0.0
1.0.1
1.0.2
Fixed in
0.11.3
0.12.4
0.13.2
1.0.3
References Updated Sep 10, 2026 · Source: OSV.dev | ||
0.10.0.3
patch
2 CVEs
CVE-2025-61594
GHSA-j4pr-3wm6-xx2r
Dec 30, 2025
URI Credential Leakage Bypass over CVE-2025-27221
Low
Network
Low
None
None
ImpactIn affected URI version, a bypass exists for the fix to CVE-2025-27221 that can expose user credentials. When using the The vulnerability affects the
PatchesUpgrade to 0.12.5, 0.13.3 or 1.0.4 References
Affected versions
0.10.0
0.10.0.1
0.10.0.2
0.10.0.3
0.10.1
0.10.2
0.10.3
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
+ 11 more Show less
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.13.2
1.0.0
1.0.1
1.0.2
1.0.3
Fixed in
0.12.5
0.13.3
1.0.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-27221
GHSA-22h5-pq3x-2gf2
Mar 03, 2025
URI allows for userinfo Leakage in URI#join, URI#merge, and URI#+
Low
Local
Low
None
None
There is a possibility for userinfo leakage by in the uri gem. This vulnerability has been assigned the CVE identifier CVE-2025-27221. We recommend upgrading the uri gem. DetailsThe methods Please update URI gem to version 0.11.3, 0.12.4, 0.13.2, 1.0.3 or later. Affected versionsuri gem versions < 0.11.3, 0.12.0 to 0.12.3, 0.13.0, 0.13.1 and 1.0.0 to 1.0.2. CreditsThanks to Tsubasa Irisawa (lambdasawa) for discovering this issue. Also thanks to nobu for additional fixes of this vulnerability. Affected versions
0.10.0
0.10.0.1
0.10.0.2
0.10.0.3
0.10.1
0.10.2
0.10.3
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
+ 7 more Show less
0.12.2
0.12.3
0.13.0
0.13.1
1.0.0
1.0.1
1.0.2
Fixed in
0.11.3
0.12.4
0.13.2
1.0.3
References Updated Sep 10, 2026 · Source: OSV.dev | ||
0.11.1
patch
3 CVEs
CVE-2025-61594
GHSA-j4pr-3wm6-xx2r
Dec 30, 2025
URI Credential Leakage Bypass over CVE-2025-27221
Low
Network
Low
None
None
ImpactIn affected URI version, a bypass exists for the fix to CVE-2025-27221 that can expose user credentials. When using the The vulnerability affects the
PatchesUpgrade to 0.12.5, 0.13.3 or 1.0.4 References
Affected versions
0.10.0
0.10.0.1
0.10.0.2
0.10.0.3
0.10.1
0.10.2
0.10.3
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
+ 11 more Show less
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.13.2
1.0.0
1.0.1
1.0.2
1.0.3
Fixed in
0.12.5
0.13.3
1.0.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-27221
GHSA-22h5-pq3x-2gf2
Mar 03, 2025
URI allows for userinfo Leakage in URI#join, URI#merge, and URI#+
Low
Local
Low
None
None
There is a possibility for userinfo leakage by in the uri gem. This vulnerability has been assigned the CVE identifier CVE-2025-27221. We recommend upgrading the uri gem. DetailsThe methods Please update URI gem to version 0.11.3, 0.12.4, 0.13.2, 1.0.3 or later. Affected versionsuri gem versions < 0.11.3, 0.12.0 to 0.12.3, 0.13.0, 0.13.1 and 1.0.0 to 1.0.2. CreditsThanks to Tsubasa Irisawa (lambdasawa) for discovering this issue. Also thanks to nobu for additional fixes of this vulnerability. Affected versions
0.10.0
0.10.0.1
0.10.0.2
0.10.0.3
0.10.1
0.10.2
0.10.3
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
+ 7 more Show less
0.12.2
0.12.3
0.13.0
0.13.1
1.0.0
1.0.1
1.0.2
Fixed in
0.11.3
0.12.4
0.13.2
1.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-36617
GHSA-hww2-5g85-429m
Jun 29, 2023
URI gem has ReDoS vulnerability
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
A ReDoS issue was discovered in the URI component before 0.12.2 for Ruby. The URI parser mishandles invalid URLs that have specific characters. There is an increase in execution time for parsing strings to URI objects with NOTE: this issue exists becuse of an incomplete fix for CVE-2023-28755. Version 0.10.3 is also a fixed version. The Ruby advisory recommends updating the uri gem to 0.12.2. In order to ensure compatibility with the bundled version in older Ruby series, you may update as follows instead:
You can use gem update uri to update it. If you are using bundler, please add gem Affected versions
0.10.1
0.10.2
0.12.0
0.12.1
0.11.0
0.11.1
0.10.0
0.10.0.1
0.10.0.2
Fixed in
0.10.0.3
0.10.3
0.11.2
0.12.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.10.2
patch
3 CVEs
CVE-2025-61594
GHSA-j4pr-3wm6-xx2r
Dec 30, 2025
URI Credential Leakage Bypass over CVE-2025-27221
Low
Network
Low
None
None
ImpactIn affected URI version, a bypass exists for the fix to CVE-2025-27221 that can expose user credentials. When using the The vulnerability affects the
PatchesUpgrade to 0.12.5, 0.13.3 or 1.0.4 References
Affected versions
0.10.0
0.10.0.1
0.10.0.2
0.10.0.3
0.10.1
0.10.2
0.10.3
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
+ 11 more Show less
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.13.2
1.0.0
1.0.1
1.0.2
1.0.3
Fixed in
0.12.5
0.13.3
1.0.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-27221
GHSA-22h5-pq3x-2gf2
Mar 03, 2025
URI allows for userinfo Leakage in URI#join, URI#merge, and URI#+
Low
Local
Low
None
None
There is a possibility for userinfo leakage by in the uri gem. This vulnerability has been assigned the CVE identifier CVE-2025-27221. We recommend upgrading the uri gem. DetailsThe methods Please update URI gem to version 0.11.3, 0.12.4, 0.13.2, 1.0.3 or later. Affected versionsuri gem versions < 0.11.3, 0.12.0 to 0.12.3, 0.13.0, 0.13.1 and 1.0.0 to 1.0.2. CreditsThanks to Tsubasa Irisawa (lambdasawa) for discovering this issue. Also thanks to nobu for additional fixes of this vulnerability. Affected versions
0.10.0
0.10.0.1
0.10.0.2
0.10.0.3
0.10.1
0.10.2
0.10.3
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
+ 7 more Show less
0.12.2
0.12.3
0.13.0
0.13.1
1.0.0
1.0.1
1.0.2
Fixed in
0.11.3
0.12.4
0.13.2
1.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-36617
GHSA-hww2-5g85-429m
Jun 29, 2023
URI gem has ReDoS vulnerability
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
A ReDoS issue was discovered in the URI component before 0.12.2 for Ruby. The URI parser mishandles invalid URLs that have specific characters. There is an increase in execution time for parsing strings to URI objects with NOTE: this issue exists becuse of an incomplete fix for CVE-2023-28755. Version 0.10.3 is also a fixed version. The Ruby advisory recommends updating the uri gem to 0.12.2. In order to ensure compatibility with the bundled version in older Ruby series, you may update as follows instead:
You can use gem update uri to update it. If you are using bundler, please add gem Affected versions
0.10.1
0.10.2
0.12.0
0.12.1
0.11.0
0.11.1
0.10.0
0.10.0.1
0.10.0.2
Fixed in
0.10.0.3
0.10.3
0.11.2
0.12.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.12.1
patch
3 CVEs
CVE-2025-61594
GHSA-j4pr-3wm6-xx2r
Dec 30, 2025
URI Credential Leakage Bypass over CVE-2025-27221
Low
Network
Low
None
None
ImpactIn affected URI version, a bypass exists for the fix to CVE-2025-27221 that can expose user credentials. When using the The vulnerability affects the
PatchesUpgrade to 0.12.5, 0.13.3 or 1.0.4 References
Affected versions
0.10.0
0.10.0.1
0.10.0.2
0.10.0.3
0.10.1
0.10.2
0.10.3
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
+ 11 more Show less
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.13.2
1.0.0
1.0.1
1.0.2
1.0.3
Fixed in
0.12.5
0.13.3
1.0.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-27221
GHSA-22h5-pq3x-2gf2
Mar 03, 2025
URI allows for userinfo Leakage in URI#join, URI#merge, and URI#+
Low
Local
Low
None
None
There is a possibility for userinfo leakage by in the uri gem. This vulnerability has been assigned the CVE identifier CVE-2025-27221. We recommend upgrading the uri gem. DetailsThe methods Please update URI gem to version 0.11.3, 0.12.4, 0.13.2, 1.0.3 or later. Affected versionsuri gem versions < 0.11.3, 0.12.0 to 0.12.3, 0.13.0, 0.13.1 and 1.0.0 to 1.0.2. CreditsThanks to Tsubasa Irisawa (lambdasawa) for discovering this issue. Also thanks to nobu for additional fixes of this vulnerability. Affected versions
0.10.0
0.10.0.1
0.10.0.2
0.10.0.3
0.10.1
0.10.2
0.10.3
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
+ 7 more Show less
0.12.2
0.12.3
0.13.0
0.13.1
1.0.0
1.0.1
1.0.2
Fixed in
0.11.3
0.12.4
0.13.2
1.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-36617
GHSA-hww2-5g85-429m
Jun 29, 2023
URI gem has ReDoS vulnerability
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
A ReDoS issue was discovered in the URI component before 0.12.2 for Ruby. The URI parser mishandles invalid URLs that have specific characters. There is an increase in execution time for parsing strings to URI objects with NOTE: this issue exists becuse of an incomplete fix for CVE-2023-28755. Version 0.10.3 is also a fixed version. The Ruby advisory recommends updating the uri gem to 0.12.2. In order to ensure compatibility with the bundled version in older Ruby series, you may update as follows instead:
You can use gem update uri to update it. If you are using bundler, please add gem Affected versions
0.10.1
0.10.2
0.12.0
0.12.1
0.11.0
0.11.1
0.10.0
0.10.0.1
0.10.0.2
Fixed in
0.10.0.3
0.10.3
0.11.2
0.12.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.10.0.1
patch
3 CVEs
CVE-2025-61594
GHSA-j4pr-3wm6-xx2r
Dec 30, 2025
URI Credential Leakage Bypass over CVE-2025-27221
Low
Network
Low
None
None
ImpactIn affected URI version, a bypass exists for the fix to CVE-2025-27221 that can expose user credentials. When using the The vulnerability affects the
PatchesUpgrade to 0.12.5, 0.13.3 or 1.0.4 References
Affected versions
0.10.0
0.10.0.1
0.10.0.2
0.10.0.3
0.10.1
0.10.2
0.10.3
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
+ 11 more Show less
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.13.2
1.0.0
1.0.1
1.0.2
1.0.3
Fixed in
0.12.5
0.13.3
1.0.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-27221
GHSA-22h5-pq3x-2gf2
Mar 03, 2025
URI allows for userinfo Leakage in URI#join, URI#merge, and URI#+
Low
Local
Low
None
None
There is a possibility for userinfo leakage by in the uri gem. This vulnerability has been assigned the CVE identifier CVE-2025-27221. We recommend upgrading the uri gem. DetailsThe methods Please update URI gem to version 0.11.3, 0.12.4, 0.13.2, 1.0.3 or later. Affected versionsuri gem versions < 0.11.3, 0.12.0 to 0.12.3, 0.13.0, 0.13.1 and 1.0.0 to 1.0.2. CreditsThanks to Tsubasa Irisawa (lambdasawa) for discovering this issue. Also thanks to nobu for additional fixes of this vulnerability. Affected versions
0.10.0
0.10.0.1
0.10.0.2
0.10.0.3
0.10.1
0.10.2
0.10.3
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
+ 7 more Show less
0.12.2
0.12.3
0.13.0
0.13.1
1.0.0
1.0.1
1.0.2
Fixed in
0.11.3
0.12.4
0.13.2
1.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-36617
GHSA-hww2-5g85-429m
Jun 29, 2023
URI gem has ReDoS vulnerability
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
A ReDoS issue was discovered in the URI component before 0.12.2 for Ruby. The URI parser mishandles invalid URLs that have specific characters. There is an increase in execution time for parsing strings to URI objects with NOTE: this issue exists becuse of an incomplete fix for CVE-2023-28755. Version 0.10.3 is also a fixed version. The Ruby advisory recommends updating the uri gem to 0.12.2. In order to ensure compatibility with the bundled version in older Ruby series, you may update as follows instead:
You can use gem update uri to update it. If you are using bundler, please add gem Affected versions
0.10.1
0.10.2
0.12.0
0.12.1
0.11.0
0.11.1
0.10.0
0.10.0.1
0.10.0.2
Fixed in
0.10.0.3
0.10.3
0.11.2
0.12.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.10.0.2
patch
3 CVEs
CVE-2025-61594
GHSA-j4pr-3wm6-xx2r
Dec 30, 2025
URI Credential Leakage Bypass over CVE-2025-27221
Low
Network
Low
None
None
ImpactIn affected URI version, a bypass exists for the fix to CVE-2025-27221 that can expose user credentials. When using the The vulnerability affects the
PatchesUpgrade to 0.12.5, 0.13.3 or 1.0.4 References
Affected versions
0.10.0
0.10.0.1
0.10.0.2
0.10.0.3
0.10.1
0.10.2
0.10.3
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
+ 11 more Show less
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.13.2
1.0.0
1.0.1
1.0.2
1.0.3
Fixed in
0.12.5
0.13.3
1.0.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-27221
GHSA-22h5-pq3x-2gf2
Mar 03, 2025
URI allows for userinfo Leakage in URI#join, URI#merge, and URI#+
Low
Local
Low
None
None
There is a possibility for userinfo leakage by in the uri gem. This vulnerability has been assigned the CVE identifier CVE-2025-27221. We recommend upgrading the uri gem. DetailsThe methods Please update URI gem to version 0.11.3, 0.12.4, 0.13.2, 1.0.3 or later. Affected versionsuri gem versions < 0.11.3, 0.12.0 to 0.12.3, 0.13.0, 0.13.1 and 1.0.0 to 1.0.2. CreditsThanks to Tsubasa Irisawa (lambdasawa) for discovering this issue. Also thanks to nobu for additional fixes of this vulnerability. Affected versions
0.10.0
0.10.0.1
0.10.0.2
0.10.0.3
0.10.1
0.10.2
0.10.3
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
+ 7 more Show less
0.12.2
0.12.3
0.13.0
0.13.1
1.0.0
1.0.1
1.0.2
Fixed in
0.11.3
0.12.4
0.13.2
1.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-36617
GHSA-hww2-5g85-429m
Jun 29, 2023
URI gem has ReDoS vulnerability
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
A ReDoS issue was discovered in the URI component before 0.12.2 for Ruby. The URI parser mishandles invalid URLs that have specific characters. There is an increase in execution time for parsing strings to URI objects with NOTE: this issue exists becuse of an incomplete fix for CVE-2023-28755. Version 0.10.3 is also a fixed version. The Ruby advisory recommends updating the uri gem to 0.12.2. In order to ensure compatibility with the bundled version in older Ruby series, you may update as follows instead:
You can use gem update uri to update it. If you are using bundler, please add gem Affected versions
0.10.1
0.10.2
0.12.0
0.12.1
0.11.0
0.11.1
0.10.0
0.10.0.1
0.10.0.2
Fixed in
0.10.0.3
0.10.3
0.11.2
0.12.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.12.0
minor
4 CVEs
CVE-2025-61594
GHSA-j4pr-3wm6-xx2r
Dec 30, 2025
URI Credential Leakage Bypass over CVE-2025-27221
Low
Network
Low
None
None
ImpactIn affected URI version, a bypass exists for the fix to CVE-2025-27221 that can expose user credentials. When using the The vulnerability affects the
PatchesUpgrade to 0.12.5, 0.13.3 or 1.0.4 References
Affected versions
0.10.0
0.10.0.1
0.10.0.2
0.10.0.3
0.10.1
0.10.2
0.10.3
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
+ 11 more Show less
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.13.2
1.0.0
1.0.1
1.0.2
1.0.3
Fixed in
0.12.5
0.13.3
1.0.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-27221
GHSA-22h5-pq3x-2gf2
Mar 03, 2025
URI allows for userinfo Leakage in URI#join, URI#merge, and URI#+
Low
Local
Low
None
None
There is a possibility for userinfo leakage by in the uri gem. This vulnerability has been assigned the CVE identifier CVE-2025-27221. We recommend upgrading the uri gem. DetailsThe methods Please update URI gem to version 0.11.3, 0.12.4, 0.13.2, 1.0.3 or later. Affected versionsuri gem versions < 0.11.3, 0.12.0 to 0.12.3, 0.13.0, 0.13.1 and 1.0.0 to 1.0.2. CreditsThanks to Tsubasa Irisawa (lambdasawa) for discovering this issue. Also thanks to nobu for additional fixes of this vulnerability. Affected versions
0.10.0
0.10.0.1
0.10.0.2
0.10.0.3
0.10.1
0.10.2
0.10.3
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
+ 7 more Show less
0.12.2
0.12.3
0.13.0
0.13.1
1.0.0
1.0.1
1.0.2
Fixed in
0.11.3
0.12.4
0.13.2
1.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-36617
GHSA-hww2-5g85-429m
Jun 29, 2023
URI gem has ReDoS vulnerability
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
A ReDoS issue was discovered in the URI component before 0.12.2 for Ruby. The URI parser mishandles invalid URLs that have specific characters. There is an increase in execution time for parsing strings to URI objects with NOTE: this issue exists becuse of an incomplete fix for CVE-2023-28755. Version 0.10.3 is also a fixed version. The Ruby advisory recommends updating the uri gem to 0.12.2. In order to ensure compatibility with the bundled version in older Ruby series, you may update as follows instead:
You can use gem update uri to update it. If you are using bundler, please add gem Affected versions
0.10.1
0.10.2
0.12.0
0.12.1
0.11.0
0.11.1
0.10.0
0.10.0.1
0.10.0.2
Fixed in
0.10.0.3
0.10.3
0.11.2
0.12.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-28755
GHSA-hv5j-3h9f-99c2
Mar 31, 2023
Ruby URI component ReDoS issue
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A ReDoS issue was discovered in the URI component through 0.12.0 in Ruby through 3.2.1. The URI parser mishandles invalid URLs that have specific characters. It causes an increase in execution time for parsing strings to URI objects. The fixed versions are 0.12.1, 0.11.1, 0.10.2 and 0.10.0.1. Affected versions
0.12.0
0.11.0
0.10.1
0.10.0
Fixed in
0.10.0.1
0.10.2
0.11.1
0.12.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.11.0
minor
4 CVEs
CVE-2025-61594
GHSA-j4pr-3wm6-xx2r
Dec 30, 2025
URI Credential Leakage Bypass over CVE-2025-27221
Low
Network
Low
None
None
ImpactIn affected URI version, a bypass exists for the fix to CVE-2025-27221 that can expose user credentials. When using the The vulnerability affects the
PatchesUpgrade to 0.12.5, 0.13.3 or 1.0.4 References
Affected versions
0.10.0
0.10.0.1
0.10.0.2
0.10.0.3
0.10.1
0.10.2
0.10.3
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
+ 11 more Show less
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.13.2
1.0.0
1.0.1
1.0.2
1.0.3
Fixed in
0.12.5
0.13.3
1.0.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-27221
GHSA-22h5-pq3x-2gf2
Mar 03, 2025
URI allows for userinfo Leakage in URI#join, URI#merge, and URI#+
Low
Local
Low
None
None
There is a possibility for userinfo leakage by in the uri gem. This vulnerability has been assigned the CVE identifier CVE-2025-27221. We recommend upgrading the uri gem. DetailsThe methods Please update URI gem to version 0.11.3, 0.12.4, 0.13.2, 1.0.3 or later. Affected versionsuri gem versions < 0.11.3, 0.12.0 to 0.12.3, 0.13.0, 0.13.1 and 1.0.0 to 1.0.2. CreditsThanks to Tsubasa Irisawa (lambdasawa) for discovering this issue. Also thanks to nobu for additional fixes of this vulnerability. Affected versions
0.10.0
0.10.0.1
0.10.0.2
0.10.0.3
0.10.1
0.10.2
0.10.3
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
+ 7 more Show less
0.12.2
0.12.3
0.13.0
0.13.1
1.0.0
1.0.1
1.0.2
Fixed in
0.11.3
0.12.4
0.13.2
1.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-36617
GHSA-hww2-5g85-429m
Jun 29, 2023
URI gem has ReDoS vulnerability
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
A ReDoS issue was discovered in the URI component before 0.12.2 for Ruby. The URI parser mishandles invalid URLs that have specific characters. There is an increase in execution time for parsing strings to URI objects with NOTE: this issue exists becuse of an incomplete fix for CVE-2023-28755. Version 0.10.3 is also a fixed version. The Ruby advisory recommends updating the uri gem to 0.12.2. In order to ensure compatibility with the bundled version in older Ruby series, you may update as follows instead:
You can use gem update uri to update it. If you are using bundler, please add gem Affected versions
0.10.1
0.10.2
0.12.0
0.12.1
0.11.0
0.11.1
0.10.0
0.10.0.1
0.10.0.2
Fixed in
0.10.0.3
0.10.3
0.11.2
0.12.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-28755
GHSA-hv5j-3h9f-99c2
Mar 31, 2023
Ruby URI component ReDoS issue
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A ReDoS issue was discovered in the URI component through 0.12.0 in Ruby through 3.2.1. The URI parser mishandles invalid URLs that have specific characters. It causes an increase in execution time for parsing strings to URI objects. The fixed versions are 0.12.1, 0.11.1, 0.10.2 and 0.10.0.1. Affected versions
0.12.0
0.11.0
0.10.1
0.10.0
Fixed in
0.10.0.1
0.10.2
0.11.1
0.12.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.10.1
patch
4 CVEs
CVE-2025-61594
GHSA-j4pr-3wm6-xx2r
Dec 30, 2025
URI Credential Leakage Bypass over CVE-2025-27221
Low
Network
Low
None
None
ImpactIn affected URI version, a bypass exists for the fix to CVE-2025-27221 that can expose user credentials. When using the The vulnerability affects the
PatchesUpgrade to 0.12.5, 0.13.3 or 1.0.4 References
Affected versions
0.10.0
0.10.0.1
0.10.0.2
0.10.0.3
0.10.1
0.10.2
0.10.3
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
+ 11 more Show less
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.13.2
1.0.0
1.0.1
1.0.2
1.0.3
Fixed in
0.12.5
0.13.3
1.0.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-27221
GHSA-22h5-pq3x-2gf2
Mar 03, 2025
URI allows for userinfo Leakage in URI#join, URI#merge, and URI#+
Low
Local
Low
None
None
There is a possibility for userinfo leakage by in the uri gem. This vulnerability has been assigned the CVE identifier CVE-2025-27221. We recommend upgrading the uri gem. DetailsThe methods Please update URI gem to version 0.11.3, 0.12.4, 0.13.2, 1.0.3 or later. Affected versionsuri gem versions < 0.11.3, 0.12.0 to 0.12.3, 0.13.0, 0.13.1 and 1.0.0 to 1.0.2. CreditsThanks to Tsubasa Irisawa (lambdasawa) for discovering this issue. Also thanks to nobu for additional fixes of this vulnerability. Affected versions
0.10.0
0.10.0.1
0.10.0.2
0.10.0.3
0.10.1
0.10.2
0.10.3
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
+ 7 more Show less
0.12.2
0.12.3
0.13.0
0.13.1
1.0.0
1.0.1
1.0.2
Fixed in
0.11.3
0.12.4
0.13.2
1.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-36617
GHSA-hww2-5g85-429m
Jun 29, 2023
URI gem has ReDoS vulnerability
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
A ReDoS issue was discovered in the URI component before 0.12.2 for Ruby. The URI parser mishandles invalid URLs that have specific characters. There is an increase in execution time for parsing strings to URI objects with NOTE: this issue exists becuse of an incomplete fix for CVE-2023-28755. Version 0.10.3 is also a fixed version. The Ruby advisory recommends updating the uri gem to 0.12.2. In order to ensure compatibility with the bundled version in older Ruby series, you may update as follows instead:
You can use gem update uri to update it. If you are using bundler, please add gem Affected versions
0.10.1
0.10.2
0.12.0
0.12.1
0.11.0
0.11.1
0.10.0
0.10.0.1
0.10.0.2
Fixed in
0.10.0.3
0.10.3
0.11.2
0.12.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-28755
GHSA-hv5j-3h9f-99c2
Mar 31, 2023
Ruby URI component ReDoS issue
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A ReDoS issue was discovered in the URI component through 0.12.0 in Ruby through 3.2.1. The URI parser mishandles invalid URLs that have specific characters. It causes an increase in execution time for parsing strings to URI objects. The fixed versions are 0.12.1, 0.11.1, 0.10.2 and 0.10.0.1. Affected versions
0.12.0
0.11.0
0.10.1
0.10.0
Fixed in
0.10.0.1
0.10.2
0.11.1
0.12.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.10.0
initial
4 CVEs
CVE-2025-61594
GHSA-j4pr-3wm6-xx2r
Dec 30, 2025
URI Credential Leakage Bypass over CVE-2025-27221
Low
Network
Low
None
None
ImpactIn affected URI version, a bypass exists for the fix to CVE-2025-27221 that can expose user credentials. When using the The vulnerability affects the
PatchesUpgrade to 0.12.5, 0.13.3 or 1.0.4 References
Affected versions
0.10.0
0.10.0.1
0.10.0.2
0.10.0.3
0.10.1
0.10.2
0.10.3
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
+ 11 more Show less
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.13.2
1.0.0
1.0.1
1.0.2
1.0.3
Fixed in
0.12.5
0.13.3
1.0.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-27221
GHSA-22h5-pq3x-2gf2
Mar 03, 2025
URI allows for userinfo Leakage in URI#join, URI#merge, and URI#+
Low
Local
Low
None
None
There is a possibility for userinfo leakage by in the uri gem. This vulnerability has been assigned the CVE identifier CVE-2025-27221. We recommend upgrading the uri gem. DetailsThe methods Please update URI gem to version 0.11.3, 0.12.4, 0.13.2, 1.0.3 or later. Affected versionsuri gem versions < 0.11.3, 0.12.0 to 0.12.3, 0.13.0, 0.13.1 and 1.0.0 to 1.0.2. CreditsThanks to Tsubasa Irisawa (lambdasawa) for discovering this issue. Also thanks to nobu for additional fixes of this vulnerability. Affected versions
0.10.0
0.10.0.1
0.10.0.2
0.10.0.3
0.10.1
0.10.2
0.10.3
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
+ 7 more Show less
0.12.2
0.12.3
0.13.0
0.13.1
1.0.0
1.0.1
1.0.2
Fixed in
0.11.3
0.12.4
0.13.2
1.0.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-36617
GHSA-hww2-5g85-429m
Jun 29, 2023
URI gem has ReDoS vulnerability
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
A ReDoS issue was discovered in the URI component before 0.12.2 for Ruby. The URI parser mishandles invalid URLs that have specific characters. There is an increase in execution time for parsing strings to URI objects with NOTE: this issue exists becuse of an incomplete fix for CVE-2023-28755. Version 0.10.3 is also a fixed version. The Ruby advisory recommends updating the uri gem to 0.12.2. In order to ensure compatibility with the bundled version in older Ruby series, you may update as follows instead:
You can use gem update uri to update it. If you are using bundler, please add gem Affected versions
0.10.1
0.10.2
0.12.0
0.12.1
0.11.0
0.11.1
0.10.0
0.10.0.1
0.10.0.2
Fixed in
0.10.0.3
0.10.3
0.11.2
0.12.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-28755
GHSA-hv5j-3h9f-99c2
Mar 31, 2023
Ruby URI component ReDoS issue
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A ReDoS issue was discovered in the URI component through 0.12.0 in Ruby through 3.2.1. The URI parser mishandles invalid URLs that have specific characters. It causes an increase in execution time for parsing strings to URI objects. The fixed versions are 0.12.1, 0.11.1, 0.10.2 and 0.10.0.1. Affected versions
0.12.0
0.11.0
0.10.1
0.10.0
Fixed in
0.10.0.1
0.10.2
0.11.1
0.12.1
References
Updated Sep 10, 2026 · Source: OSV.dev |