Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-hm5p-x4rq-38w4 | httparty Has Potential SSRF Vulnerability That Leads to API Key Leakage |
Wed, 07 Jan 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jnunemaker
Jnunemaker httparty |
|
| CPEs | cpe:2.3:a:jnunemaker:httparty:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Jnunemaker
Jnunemaker httparty |
|
| Metrics |
cvssV3_1
|
cvssV3_1
|
Wed, 24 Dec 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 24 Dec 2025 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Wed, 24 Dec 2025 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
John Nunemaker
John Nunemaker httparty |
|
| Vendors & Products |
John Nunemaker
John Nunemaker httparty |
Tue, 23 Dec 2025 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | httparty is an API tool. In versions 0.23.2 and prior, httparty is vulnerable to SSRF. This issue can pose a risk of leaking API keys, and it can also allow third parties to issue requests to internal servers. This issue has been patched via commit 0529bcd. | |
| Title | httparty Has Potential SSRF Vulnerability That Leads to API Key Leakage | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-12-24T14:31:58.017Z
Reserved: 2025-12-23T17:11:35.076Z
Link: CVE-2025-68696
Updated: 2025-12-24T14:31:44.582Z
Status : Analyzed
Published: 2025-12-23T23:15:45.627
Modified: 2026-04-29T01:00:01.613
Link: CVE-2025-68696
OpenCVE Enrichment
Updated: 2025-12-24T11:51:40Z
Github GHSA