CVE-2025-27221: Ruby-Lang Uri
Medium severity, CVSS 5.3. EPSS: 0.5% chance of exploitation in the next 30 days.
In the URI gem before 1.0.3 for Ruby, the URI handling methods (URI.join, URI#merge, URI#+) have an inadvertent leakage of authentication credentials because userinfo is retained even after changing the host.
Affected products
- Ruby-Lang Uri: before 0.11.3 (fixed in 0.11.3); from 0.12.0, before 0.12.4 (fixed in 0.12.4); from 0.13.0, before 0.13.2 (fixed in 0.13.2); from 1.0.0, before 1.0.3 (fixed in 1.0.3)
Published 2025-03-04. Last modified 2026-06-17.