/
DirectorySecurity Advisories
Sign In
Security Advisories

CVE-2025-27221

Published

Last updated

NVD

https://nvd.nist.gov/vuln/detail/CVE-2025-27221

CGA ID

CGA-g9vr-7jx4-v7vv

Severity

Unknown

Description

In the URI gem before 1.0.3 for Ruby, the URI handling methods (URI.join, URI#merge, URI#+) have an inadvertent leakage of authentication credentials because userinfo is retained even after changing the host.

References

  • https://images.chainguard.dev/security/CGA-g9vr-7jx4-v7vv

Affected packages


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Products

Chainguard ContainersChainguard LibrariesChainguard VMs