uri is vulnerable to Improper Removal of Sensitive Information Before Storage or Transfer
50
Medium Risk
In affected versions of uri, a bypass for the fix to CVE-2025-27221 can lead to credential exposure. This vulnerability is tracked as CVE-2025-61594. We recommend upgrading the uri gem. When using the + operator to combine URIs, sensitive data such as passwords from the original URI may be leaked, violating RFC 3986 and exposing applications to credential disclosure.
You are affected if you are using a vulnerable version of the package.
uri is vulnerable to Improper Removal of Sensitive Information Before Storage or Transfer in versions 0.0.1 - 0.12.4, 0.13.0 - 0.13.2 and 1.0.0 - 1.0.3.
Upgrade uri to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant