Server-Side Request Forgery (SSRF) in faraday - CVE-2026-33637
Published: May 18, 2026
faraday
Detailed vulnerability description
The vulnerability allows a remote attacker to redirect requests to an attacker-controlled host.
The vulnerability exists due to server-side request forgery in Faraday::Connection#build_exclusive_url when processing a protocol-relative URI object as a per-request target. A remote attacker can supply a crafted protocol-relative URI object to redirect requests to an attacker-controlled host.
Connection-scoped headers such as Authorization may be preserved on the off-host request.