Jnunemaker maintains HTTParty, a lightweight HTTP client library for Ruby, with a focused vulnerability profile centered on web request handling. The durable signal consists of external parameter control and server-side request forgery vulnerabilities, which reflect the library's role in constructing and dispatching HTTP requests and the risks inherent to flexible request-parameter handling. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Jnunemaker over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-68696HIGH httparty is an API tool. In versions 0.23.2 and prior, httparty is vulnerable to SSRF. This issue can pose a risk of leaking API keys, and it can also allow third parties to issue | Dec 23, 2025 | 8.2 | 26 | NO | NO |
CVE-2013-1801HIGH The httparty gem 0.9.0 and earlier for Ruby does not properly restrict casts of string values, which might allow remote attackers to conduct object-injection attacks and execute ar | Apr 9, 2013 | 7.5 | 25 | NO | NO |
CVE-2024-22049MEDIUM httparty before 0.21.0 is vulnerable to an assumed-immutable web parameter vulnerability. A remote and unauthenticated attacker can provide a crafted filename parameter during mult | Jan 4, 2024 | 5.3 | 19 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Jnunemaker.
Media articles that mention a CVE ID that affects a product developed by Jnunemaker — matched by CVE ID, not by vendor name.