Uri
5 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Uri, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
Uri CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 1 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 1 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 5 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- High1
- Medium3
- Low1
Latest CVEs
The 5 most recently published vulnerabilities affecting Uri.
- CVE-2025-61594URI Credential Leakage Bypass over CVE-2025-272217.5
- CVE-2025-27221In the URI gem before 1.0.3 for Ruby, the URI handling methods (URI.join, URI#merge, URI#+) have an inadvertent leakage of authentication credentials because userinfo is retained even after changin...3.2
- CVE-2023-36617A ReDoS issue was discovered in the URI component before 0.12.2 for Ruby. The URI parser mishandles invalid URLs that have specific characters. There is an increase in execution time for parsing st...5.3
- CVE-2023-28755A ReDoS issue was discovered in the URI component through 0.12.0 in Ruby through 3.2.1. The URI parser mishandles invalid URLs that have specific characters. It causes an increase in execution time...5.3
- CVE-2023-28628`authority-regex` returns the wrong authority in lambdaisland/uri5.4
Product grouping is registry-driven, with AI assist and human review. How it works