Intel

AIKIDO-2025-10665

uri is vulnerable to Improper Removal of Sensitive Information Before Storage or Transfer

Improper Removal of Sensitive Information Before Storage or TransferCVE-2025-61594 Published Oct 7, 2025

50

Medium Risk

This Affects:

RUBYuri
0.0.1 - 0.12.4
Fixed in 0.12.5
0.13.0 - 0.13.2
Fixed in 0.13.3
1.0.0 - 1.0.3
Fixed in 1.0.4
Are you affected? Scan for Free

TL;DR

In affected versions of uri, a bypass for the fix to CVE-2025-27221 can lead to credential exposure. This vulnerability is tracked as CVE-2025-61594. We recommend upgrading the uri gem. When using the + operator to combine URIs, sensitive data such as passwords from the original URI may be leaked, violating RFC 3986 and exposing applications to credential disclosure.

Who does this affect?

You are affected if you are using a vulnerable version of the package.

Background info

uri is vulnerable to Improper Removal of Sensitive Information Before Storage or Transfer in versions 0.0.1 - 0.12.4, 0.13.0 - 0.13.2 and 1.0.0 - 1.0.3.

How to fix this

Upgrade uri to the patch version.