httparty
RubyGems3 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting httpartypage 1 of 1
- CVE-2013-1801NONECVSS 0.0✓ Fixed in 0.10.02013-04-09
vulnerable: 0.1.0 ... 0.9.0 (44 versions)
The httparty gem 0.9.0 and earlier for Ruby does not properly restrict casts of string values, which might allow remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU …
- CVE-2024-22049MEDIUMCVSS 5.3EG 5.3✓ Fixed in 0.21.02024-01-04
vulnerable: 0.1.0 ... 0.9.0 (79 versions)
httparty before 0.21.0 is vulnerable to an assumed-immutable web parameter vulnerability. A remote and unauthenticated attacker can provide a crafted filename parameter during multipart/form-data uploads which could result in attacker cont…
- CVE-2025-68696HIGHCVSS 8.2EG 8.2✓ Fixed in 0.24.02025-12-23
vulnerable: 0.1.0 ... 0.9.0 (84 versions)
httparty is an API tool. In versions 0.23.2 and prior, httparty is vulnerable to SSRF. This issue can pose a risk of leaking API keys, and it can also allow third parties to issue requests to internal servers. This issue has been patched v…
Check whether httparty is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for httparty CVEs against the assets you own.
Start Free Scan →