#VU116663 Information disclosure in URI - CVE-2025-61594
Published: October 7, 2025
URI
rubygems.org
Description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to insufficient fix for #VU105105 (CVE-2025-27221). When using the + operator to combine URIs, sensitive information like passwords from the original URI can be leaked. A remote attacker can gain access to sensitive information.