Skip to content

Conversation

@hudakh
Copy link
Contributor

@hudakh hudakh commented Oct 27, 2025

This adds an advisory under rubies/ruby for CVE-2025-61594, affecting Ruby versions before
3.3.10 and 3.4.7. The vulnerability allows credential leakage when combining URIs using the

Fixed in Ruby 3.3.10 and 3.4.7.

@hudakh hudakh marked this pull request as ready for review October 27, 2025 06:19
@hudakh
Copy link
Contributor Author

hudakh commented Oct 27, 2025

@jasnow for your review

@jasnow
Copy link
Contributor

jasnow commented Oct 28, 2025

Please add this advisory at the bottom of your advisory:
https://github.com/rubysec/ruby-advisory-db/blob/master/gems/uri/CVE-2025-61594.yml

@hudakh
Copy link
Contributor Author

hudakh commented Oct 28, 2025

Please add this advisory at the bottom of your advisory: https://github.com/rubysec/ruby-advisory-db/blob/master/gems/uri/CVE-2025-61594.yml

Done. Thanks!

@hudakh hudakh requested a review from postmodern November 3, 2025 00:26
@hudakh hudakh requested a review from postmodern November 4, 2025 04:15
@postmodern postmodern merged commit 8107219 into rubysec:master Nov 4, 2025
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants