GHSA-j4pr-3wm6-xx2r

Suggest an improvement
Source
https://github.com/advisories/GHSA-j4pr-3wm6-xx2r
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/12/GHSA-j4pr-3wm6-xx2r/GHSA-j4pr-3wm6-xx2r.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-j4pr-3wm6-xx2r
Aliases
Downstream
CGA (101)
ECHO (1)
MINI (19)
Related
Published
2025-12-30T21:07:14Z
Modified
2026-07-17T21:03:08Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
  • 2.7 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U CVSS Calculator
Summary
URI Credential Leakage Bypass over CVE-2025-27221
Details

Impact

In affected URI version, a bypass exists for the fix to CVE-2025-27221 that can expose user credentials.

When using the + operator to combine URIs, sensitive information like passwords from the original URI can be leaked, violating RFC3986 and making applications vulnerable to credential exposure.

The vulnerability affects the uri gem bundled with the following Ruby series:

  • 0.12.4 and earlier (bundled in Ruby 3.2 series)
  • 0.13.2 and earlier (bundled in Ruby 3.3 series)
  • 1.0.3 and earlier (bundled in Ruby 3.4 series)

Patches

Upgrade to 0.12.5, 0.13.3 or 1.0.4

References

Database specific
{
    "cwe_ids":  [
        "CWE-200",
        "CWE-212"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2025-12-30T21:07:14Z",
    "nvd_published_at":  "2025-12-30T21:15:43Z",
    "severity":  "LOW"
}
References

Affected packages

RubyGems / uri

Package

Name
uri
Purl
pkg:gem/uri

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.12.5

Affected versions

0.*
0.10.0
0.10.0.1
0.10.0.2
0.10.0.3
0.10.1
0.10.2
0.10.3
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/12/GHSA-j4pr-3wm6-xx2r/GHSA-j4pr-3wm6-xx2r.json"

RubyGems / uri

Package

Name
uri
Purl
pkg:gem/uri

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0.13.0
Fixed
0.13.3

Affected versions

0.*
0.13.0
0.13.1
0.13.2

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/12/GHSA-j4pr-3wm6-xx2r/GHSA-j4pr-3wm6-xx2r.json"

RubyGems / uri

Package

Name
uri
Purl
pkg:gem/uri

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.0.0
Fixed
1.0.4

Affected versions

1.*
1.0.0
1.0.1
1.0.2
1.0.3

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/12/GHSA-j4pr-3wm6-xx2r/GHSA-j4pr-3wm6-xx2r.json"