httparty is an API tool. In versions 0.23.2 and prior, httparty is vulnerable to SSRF. This issue can pose a risk of leaking API keys, and it can also allow third parties to issue requests to internal servers. This issue has been patched via commit 0529bcd.
History

Wed, 24 Dec 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 24 Dec 2025 12:30:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N'}

threat_severity

Important


Wed, 24 Dec 2025 12:00:00 +0000

Type Values Removed Values Added
First Time appeared John Nunemaker
John Nunemaker httparty
Vendors & Products John Nunemaker
John Nunemaker httparty

Tue, 23 Dec 2025 23:15:00 +0000

Type Values Removed Values Added
Description httparty is an API tool. In versions 0.23.2 and prior, httparty is vulnerable to SSRF. This issue can pose a risk of leaking API keys, and it can also allow third parties to issue requests to internal servers. This issue has been patched via commit 0529bcd.
Title httparty Has Potential SSRF Vulnerability That Leads to API Key Leakage
Weaknesses CWE-918
References
Metrics cvssV4_0

{'score': 7.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-12-23T22:59:04.201Z

Updated: 2025-12-24T14:31:58.017Z

Reserved: 2025-12-23T17:11:35.076Z

Link: CVE-2025-68696

cve-icon Vulnrichment

Updated: 2025-12-24T14:31:44.582Z

cve-icon NVD

Status : Received

Published: 2025-12-23T23:15:45.627

Modified: 2025-12-24T15:16:04.153

Link: CVE-2025-68696

cve-icon Redhat

Severity : Important

Publid Date: 2025-12-23T22:59:04Z

Links: CVE-2025-68696 - Bugzilla