Skip to content

Add advisory for CVE-2025-61594 (URI Credential Leakage Bypass) for Ruby < 3.3.10 and < 3.4.7#913

Merged
postmodern merged 6 commits into
rubysec:masterfrom
hudakh:master
Nov 4, 2025
Merged

Add advisory for CVE-2025-61594 (URI Credential Leakage Bypass) for Ruby < 3.3.10 and < 3.4.7#913
postmodern merged 6 commits into
rubysec:masterfrom
hudakh:master

Conversation

@hudakh

@hudakh hudakh commented Oct 27, 2025

Copy link
Copy Markdown
Contributor

This adds an advisory under rubies/ruby for CVE-2025-61594, affecting Ruby versions before
3.3.10 and 3.4.7. The vulnerability allows credential leakage when combining URIs using the

Fixed in Ruby 3.3.10 and 3.4.7.

@hudakh hudakh marked this pull request as ready for review October 27, 2025 06:19
@hudakh

hudakh commented Oct 27, 2025

Copy link
Copy Markdown
Contributor Author

@jasnow for your review

@jasnow

jasnow commented Oct 28, 2025

Copy link
Copy Markdown
Member

Please add this advisory at the bottom of your advisory:
https://github.com/rubysec/ruby-advisory-db/blob/master/gems/uri/CVE-2025-61594.yml

@hudakh

hudakh commented Oct 28, 2025

Copy link
Copy Markdown
Contributor Author

Please add this advisory at the bottom of your advisory: https://github.com/rubysec/ruby-advisory-db/blob/master/gems/uri/CVE-2025-61594.yml

Done. Thanks!

Comment thread rubies/ruby/CVE-2025-61594.yml Outdated
Comment thread rubies/ruby/CVE-2025-61594.yml
@hudakh hudakh requested a review from postmodern November 3, 2025 00:26
Comment thread rubies/ruby/CVE-2025-61594.yml Outdated
@hudakh hudakh requested a review from postmodern November 4, 2025 04:15
@postmodern postmodern merged commit 8107219 into rubysec:master Nov 4, 2025
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants