Httparty
Vendor:
First CVE: Apr 9, 2013 · Active for 13 years
3
Total CVEs
More Total CVEs than 64% of tracked products
1.0
Avg CVEs / Year
Bottom 1%
7.0
Avg CVSS
Higher Avg CVSS than 41% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Httparty over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 9, 2013
13 years ago
Most Recent CVE
Dec 23, 2025
213 days ago
CVE Severity & Scoring
Httparty3 CVEs
33%
67%
All CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network2 (66.7%)
Unknown1 (33.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low2 (66.7%)
High0 (0.0%)
Unknown1 (33.3%)
User Interaction
None2 (66.7%)
Unknown1 (33.3%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None2 (66.7%)
Unknown1 (33.3%)
Top CVEs
Signals from CVEs in this product scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-68696HIGH httparty is an API tool. In versions 0.23.2 and prior, httparty is vulnerable to SSRF. This issue can pose a risk of leaking API keys, and it can also allow third parties to issue | Dec 23, 2025 | 8.2 | 26 | NO | NO |
CVE-2013-1801HIGH The httparty gem 0.9.0 and earlier for Ruby does not properly restrict casts of string values, which might allow remote attackers to conduct object-injection attacks and execute ar | Apr 9, 2013 | 7.5 | 25 | NO | NO |
CVE-2024-22049MEDIUM httparty before 0.21.0 is vulnerable to an assumed-immutable web parameter vulnerability. A remote and unauthenticated attacker can provide a crafted filename parameter during mult | Jan 4, 2024 | 5.3 | 19 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (3 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (3 CVEs).
Media Mentions
Signals from CVEs in this product scope (3 CVEs).
Top CNAs Publishing CVEs For Httparty
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 0.8.3 | 1 | 7.5 | 4.4% | 0 | 0 |
| 0.8.2 | 1 | 7.5 | 4.4% | 0 | 0 |
| 0.8.1 | 1 | 7.5 | 4.4% | 0 | 0 |
| 0.8.0 | 1 | 7.5 | 4.4% | 0 | 0 |
| 0.7.8 | 1 | 7.5 | 4.4% | 0 | 0 |
| 0.7.7 | 1 | 7.5 | 4.4% | 0 | 0 |
| 0.7.6 | 1 | 7.5 | 4.4% | 0 | 0 |
| 0.7.5 | 1 | 7.5 | 4.4% | 0 | 0 |
| 0.7.4 | 1 | 7.5 | 4.4% | 0 | 0 |
| 0.7.3 | 1 | 7.5 | 4.4% | 0 | 0 |
| 0.7.2 | 1 | 7.5 | 4.4% | 0 | 0 |
| 0.7.1 | 1 | 7.5 | 4.4% | 0 | 0 |
| 0.7.0 | 1 | 7.5 | 4.4% | 0 | 0 |
| 0.6.1 | 1 | 7.5 | 4.4% | 0 | 0 |
| 0.6.0 | 1 | 7.5 | 4.4% | 0 | 0 |
| 0.5.2 | 1 | 7.5 | 4.4% | 0 | 0 |
| 0.5.1 | 1 | 7.5 | 4.4% | 0 | 0 |
| 0.5.0 | 1 | 7.5 | 4.4% | 0 | 0 |
| 0.4.5 | 1 | 7.5 | 4.4% | 0 | 0 |
| 0.4.4 | 1 | 7.5 | 4.4% | 0 | 0 |