Information disclosure in URI - CVE-2025-61594
Published: October 7, 2025
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to insufficient fix for #VU105105 (CVE-2025-27221). When using the + operator to combine URIs, sensitive information like passwords from the original URI can be leaked. A remote attacker can gain access to sensitive information.
Affected software
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Ubuntu
openEuler
Fedora
rubygem-rss
rubygem-abrt
rubygem-abrt-doc
rubygem-mysql2-doc
rubygem-mysql2
rubygem-io-console
rubygem-typeprof
rubygem-rbs
rubygem-did_you_mean
rubygem-pg-doc
rubygem-pg
rubygem-racc
rubygem-irb
rubygem-power_assert
rubygem-openssl
rubygem-bundler
ruby2.3 (Ubuntu package)
rubygem-json
rubygem-bigdecimal
ruby-help
ruby-irb
ruby
ruby-debuginfo
ruby-debugsource
ruby-devel
rubygem-rexml
rubygems-devel
rubygems
rubygem-psych
rubygem-test-unit
ruby-default-gems
ruby-doc
ruby-bundled-gems
ruby-libs
ruby (Red Hat package)
rubygem-minitest
rubygem-rdoc
rubygem-rake
How to mitigate CVE-2025-61594
rubygem-rss - update to 0.2.9-144
rubygem-rss - update to 0.3.1-5
rubygem-abrt - update to 0.4.0-1
rubygem-abrt-doc - update to 0.4.0-1
rubygem-mysql2-doc - update to 0.5.5-1
rubygem-mysql2 - update to 0.5.5-1
rubygem-io-console - update to 0.5.7-144
rubygem-io-console - update to 0.7.1-5
rubygem-typeprof - update to 0.15.2-144
rubygem-typeprof - update to 0.21.9-5
rubygem-rbs - update to 1.4.0-144
rubygem-did_you_mean - update to 1.5.0-144
rubygem-pg-doc - update to 1.5.4-1
rubygem-pg - update to 1.5.4-1
rubygem-racc - update to 1.7.3-5
rubygem-irb - update to 1.13.1-5
rubygem-power_assert - update to 2.0.3-5
rubygem-openssl - update to 2.2.1-144
rubygem-bundler - update to 2.2.32-144
ruby2.3 (Ubuntu package) - addressed in versions 2.3.1-2~ubuntu16.04.16+esm12, 2.5.1-1ubuntu1.16+esm7, 2.7.0-5ubuntu1.18+esm4, 3.0.2-7ubuntu2.12, 3.2.3-1ubuntu0.24.04.7, 3.3.8-2ubuntu2.1
rubygem-json - update to 2.5.1-144
rubygem-bundler - update to 2.5.22-5
rubygem-json - update to 2.7.2-5
rubygem-bigdecimal - update to 3.0.0-144
ruby-help - update to 3.0.3-144
ruby-irb - update to 3.0.3-144
ruby - update to 3.0.3-144
ruby-debuginfo - update to 3.0.3-144
ruby-debugsource - update to 3.0.3-144
ruby-devel - update to 3.0.3-144
rubygem-bigdecimal - update to 3.1.5-5
rubygem-rexml - update to 3.2.5-144
rubygems-devel - update to 3.2.32-144
rubygems - update to 3.2.32-144
rubygem-psych - update to 3.3.2-144
rubygem-test-unit - update to 3.3.7-144
ruby-default-gems - update to 3.3.10-5
ruby-doc - update to 3.3.10-5
ruby - update to 3.3.10-5
ruby-bundled-gems - update to 3.3.10-5
ruby-devel - update to 3.3.10-5
ruby-libs - update to 3.3.10-5
ruby (Red Hat package) - update to 3.3.10-11.el10_1
rubygem-rbs - update to 3.4.0-5
rubygem-rexml - update to 3.4.4-5
ruby - update to 3.4.7-26.fc42
rubygems - update to 3.5.22-5
rubygems-devel - update to 3.5.22-5
rubygem-test-unit - update to 3.6.1-5
rubygem-psych - update to 5.1.2-5
rubygem-minitest - update to 5.14.2-144
rubygem-minitest - update to 5.20.0-5
rubygem-rdoc - update to 6.3.3-144
rubygem-rdoc - update to 6.6.3.1-5
rubygem-rake - update to 13.0.3-144
rubygem-rake - update to 13.1.0-5