CVE-2025-68696
- EPSS 0.06%
- Veröffentlicht 23.12.2025 22:59:04
- Zuletzt bearbeitet 07.01.2026 19:15:28
httparty is an API tool. In versions 0.23.2 and prior, httparty is vulnerable to SSRF. This issue can pose a risk of leaking API keys, and it can also allow third parties to issue requests to internal servers. This issue has been patched via commit 0...
CVE-2024-22049
- EPSS 1.19%
- Veröffentlicht 04.01.2024 21:15:10
- Zuletzt bearbeitet 07.01.2026 19:49:03
httparty before 0.21.0 is vulnerable to an assumed-immutable web parameter vulnerability. A remote and unauthenticated attacker can provide a crafted filename parameter during multipart/form-data uploads which could result in attacker controlled file...
CVE-2013-1801
- EPSS 2.99%
- Veröffentlicht 09.04.2013 20:55:01
- Zuletzt bearbeitet 07.01.2026 19:27:17
The httparty gem 0.9.0 and earlier for Ruby does not properly restrict casts of string values, which might allow remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU consumption...