CVE-2026-25765Disclosure(faraday_project / faraday)

LOWCVSS 5.8 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Faraday is an HTTP client library abstraction layer that provides a common interface over many adapters. Prior to 2.14.1, Faraday's build_exclusive_url method (in lib/faraday/connection.rb) uses Ruby's URI#merge to combine the connection's base URL with a user-supplied path. Per RFC 3986, protocol-relative URLs (e.g. //evil.com/path) are treated as network-path references that override the base URL's host/authority component. This means that if any application passes user-controlled input to Faraday's get(), post(), build_url(), or other request methods, an attacker can supply a protocol-relative URL like //attacker.com/endpoint to redirect the request to an arbitrary host, enabling Server-Side Request Forgery (SSRF). This vulnerability is fixed in 2.14.1.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • faraday

Threat summary

  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 2 mentions (2026-02-09); latest day: 1
  • 5 total mentions across 4 days

Affected systems

Products
faraday

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-02-09: 2Mentions · 2026-02-11: 1Mentions · 2026-03-10: 1Mentions · 2026-05-18: 1Technical Details · 2026-02-09: 2Technical Details · 2026-02-11: 1Technical Details · 2026-03-10: 1Technical Details · 2026-05-18: 102-0902-1103-1005-18
Signal classification2 categories
Disclosure
480.0%
General
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-02-092
Disclosure2
2026-02-111
Disclosure1
2026-03-101
General1
2026-05-181
Disclosure1
Full discourse5 posts
  • DailyCVE@dailycve
    Disclosure

    🔴 (Ruby Faraday), SSRF Bypass, #CVE-2026-25765 (High) https://dailycve.com/ruby-faraday-ssrf-bypass-cve-2026-25765-high/

    Post summary

    The text announces a newly discovered SSRF bypass vulnerability in Ruby Faraday (CVE‑2026‑25765) with high severity; no exploit, patch, or active exploitation is mentioned.

    0000060
    206 followersView on X
  • UNDERCODE TESTING@UndercodeUpdate
    General

    🚨 #AI #Copilot Neo Strikes Again: Uncovering #CVE-2026-25765 – A Deep Dive into #AI-Powered SSRF Discovery + Video https://undercodetesting.com/ai-copilot-neo-strikes-again-uncovering-cve-2026-25765-a-deep-dive-into-ai-powered-ssrf-discovery-video/ Educational Purposes!

    Post summary

    The tweet links to a video about AI‑powered SSRF discovery of CVE‑2026‑25765 but does not provide concrete PoC, exploit, patch, or active exploitation details.

    000002
    402 followersView on X
  • RUBYLAND@rubylandnews
    Disclosure

    RubySec ➜ CVE-2026-25765 (faraday): Faraday affected by SSRF via protocol-relative URL host override in build_exclusive_url https://rubysec.com/advisories/CVE-2026-25765/

    Post summary

    RubySec announces a new SSRF vulnerability in Faraday, detailing the affected component and mechanism, without providing exploit code, active exploitation evidence, or patch information.

    0000084
    2.7K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-25765 Faraday is an HTTP client library abstraction layer that provides a common interface over many adapters. Prior to 2.14.1, Faraday's build_exclusive_url method (in lib… https://www.cve.org/CVERecord?id=CVE-2026-25765

    Post summary

    The passage announces a vulnerability in Faraday’s build_exclusive_url method that existed prior to version 2.14.1.

    00000175
    56.5K followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-25765: Faraday SSRF: When a Double Slash Becomes a Double Agent A high-severity Server-Side Request Forgery (SSRF) vulnerability in the popular Ruby 'faraday' gem allows attackers to redirect HTTP requests to arbitrary hosts using protocol-re... https://cvereports.com/reports/CVE-2026-25765

    Post summary

    The report highlights a high‑severity Server‑Side Request Forgery in the Ruby Faraday gem, enabling attackers to redirect requests to arbitrary hosts.

    0000050
    27 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfaraday_projectfaraday---

Explore more