Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-61594

26
FAUCET Score

CVE-2025-61594 is a bypass to a previous fix in the Ruby URI module, affecting versions prior to 0.12.5, 0.13.3, and 1.0.4. This vulnerability allows sensitive information, specifically passwords, to be leaked when URIs are combined using the '+' operator, violating RFC3986 and leading to credential exposure. Rated with a CVSS score of 7.5 (HIGH), this vulnerability has a network attack vector and low attack complexity, requiring no user interaction or privileges, and primarily impacts confidentiality. Currently, there is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. While there's limited community discussion and media coverage, the vulnerability is not listed in CISA's KEV catalog.

Impacted Technologies

VendorProductVersion(s)CPE
< 0.12.5CPE matchmatch criteria
cpe:2.3:a:ruby-lang:uri:*:*:*:*:*:ruby:*:*
>= 0.13.0, < 0.13.3CPE matchmatch criteria
cpe:2.3:a:ruby-lang:uri:*:*:*:*:*:ruby:*:*
>= 1.0.0, < 1.0.4CPE matchmatch criteria
cpe:2.3:a:ruby-lang:uri:*:*:*:*:*:ruby:*:*

CVSS Data

CVSS version used by this source: 4.0

2.1LOW

CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
LOW
VS Integrity
NONE
VS Availability
NONE
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
UNREPORTED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.51%
Probability of exploitation in next 30 days
EPSS Percentile
40.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0051 is in the 18th percentile among its peer group of 51,506 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (24)

github_advisorypatch availablevia nvd_reference
View patch
microsoftpatch availablevia msrc
Product: azl3 ruby 3.3.5-7 on Azure Linux 3.0Fixed in: 3.3.5-7
microsoftpatch availablevia msrc
Product: 20392-17086Fixed in: 3.1.7-4
microsoftpatch availablevia msrc
Product: 20885-17086Fixed in: 3.1.7-4
microsoftpatch availablevia msrc
Product: 20884-17084Fixed in: 3.3.5-7
microsoftpatch availablevia msrc
Product: cbl2 ruby 3.1.7-3 on CBL Mariner 2.0Fixed in: 3.1.7-4
microsoftpatch availablevia msrc
Product: cbl2 ruby 3.1.7-4 on CBL Mariner 2.0Fixed in: 3.1.7-4
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: ruby:3.3-9070020251113101221.9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: ruby-0:3.3.10-11.el10_1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: ruby:3.3-8100020251124151715.489197e6
View patch
rubygemspatch availablevia ghsa
Product: uriFixed in: 0.12.5
rubygemspatch availablevia ghsa
Product: uriFixed in: 0.13.3
rubygemspatch availablevia ghsa
Product: uriFixed in: 1.0.4
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: rhel9/ruby-30
redhatvendor investigatingvia redhat_api
Product: Logging Subsystem for Red Hat OpenShiftFixed in: openshift-logging/fluentd-rhel9
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: ubi9/ruby-30
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: ubi9/ruby-33
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: rhel9/ruby-33
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: rhel10/flatpak-sdk
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: rhel10/ruby-33
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: ubi10/ruby-33
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: ubi8/ruby-33
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: rhel9/flatpak-sdk
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: rhel8/ruby-33

Vendor Advisories (3)

rubygemsGHSA-j4pr-3wm6-xx2rlow

URI Credential Leakage Bypass over CVE-2025-27221

Dec 30, 2025
redhatCVE-2025-61594Moderate

uri: URI module: Credential exposure via URI + operator

Dec 30, 2025
microsoft2025-Dec/CVE-2025-61594Low

URI Credential Leakage Bypass over CVE-2025-27221

Dec 9, 2025

References

github.com / advisories/GHSA-22h5-pq3x-2gf2
github.com / ruby/uri/security/advisories/GHSA-j4pr-3wm6-xx2r
hackerone.com / reports/2957667
ruby-lang.org / en/news/2025/02/26/security-advisories