Known vulnerabilities in URI
Vendor:
rubygems.org
Software:
URI
Software CPE:
cpe:2.3:a:rubygems.org:uri:*:*:*:*:*:ruby:*:*
Website:
https://rubygems.org
Total vulnerabilities:
4
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
8.8
Breakdown by Severity Chart
Vulnerabilities (4)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU116663 - Exposure of sensitive information to an unauthorized actor CVE-2025-61594 |
CWE-200 | Medium | 0.12.5, 0.13.3, 1.0.4 | 07.10.2025 |
SB2025100723 SB2025110338 SB2025111485 and 4 more |
||
| #VU105105 - Exposure of sensitive information to an unauthorized actor CVE-2025-27221 |
CWE-200 | Medium | 0.11.3, 0.12.4, 0.13.2, 1.0.3 | 27.02.2025 |
SB20250227241 SB2025030761 SB2025031451 and 16 more |
||
| #VU77803 - Incorrect Regular Expression CVE-2023-36617 |
CWE-185 | Medium | 0.10.3, 0.12.2 | 29.06.2023 |
SB2023062931 SB2023071289 SB2023101967 and 13 more |
||
| #VU74004 - Incorrect Regular Expression CVE-2023-28755 |
CWE-185 | Medium | 0.10.0.1, 0.10.2, 0.11.1, 0.12.1 | 24.03.2023 |
SB2023033146 SB2023042108 SB2023050430 and 41 more |