Skip to main content
Echelon
Graph
Product
Directory
Enterprise
Compliance
Pulse
Exposures
AI Analyst
Compare
Docs
Login
Start Free
Pulse
›
Vendor Advisories
›
Microsoft Security Response Center (MSRC)
›
CVE-2025-27221
CVE-2025-27221
Low
CVSS
3.2
In the URI gem before 1.0.3 for Ruby, the URI handling methods (URI.join, URI#merge, URI#+) have an inadvertent leakage of authentication credentials because userinfo is retained even after changing the host.
Vendor
Microsoft Security Response Center (MSRC)
Published
July 11, 2026
Last Modified
—
🔗 CVE IDs covered (1)
CVE-2025-27221 →