The Addressable Project maintains a focused library designed for parsing and handling address data, with its vulnerability profile concentrated in input-processing complexity. Observed weaknesses center on inefficient regular expression handling and uncontrolled resource consumption, reflecting the computational demands of comprehensive address validation and normalization. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Addressable Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-35611HIGH Addressable is an alternative implementation to the URI implementation that is part of Ruby's standard library. From 2.3.0 to before 2.9.0, within the URI template implementation i | Apr 7, 2026 | 7.5 | 27 | NO | NO |
CVE-2021-32740HIGH Addressable is an alternative implementation to the URI implementation that is part of Ruby's standard library. An uncontrolled resource consumption vulnerability exists after vers | Jul 6, 2021 | 7.5 | 25 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Addressable Project.
Media articles that mention a CVE ID that affects a product developed by Addressable Project — matched by CVE ID, not by vendor name.