AI description
CVE-2025-61594 refers to a URI credential leakage vulnerability that bypasses previous fixes. A security advisory regarding this vulnerability has been published. Additionally, CVE-2025-1594 describes a critical vulnerability in FFmpeg up to version 7.1. It affects the `ff_aac_search_for_tns` function in `libavcodec/aacenc_tns.c` of the AAC Encoder component. Exploitation of this vulnerability can lead to a stack-based buffer overflow, which can be initiated remotely.
- Description
- URI is a module providing classes to handle Uniform Resource Identifiers. In versions prior to 0.12.5, 0.13.3, and 1.0.4, a bypass exists for the fix to CVE-2025-27221 that can expose user credentials. When using the `+` operator to combine URIs, sensitive information like passwords from the original URI can be leaked, violating RFC3986 and making applications vulnerable to credential exposure. Versions 0.12.5, 0.13.3, and 1.0.4 fix the issue.
- Source
- security-advisories@github.com
- NVD status
- Awaiting Analysis
CVSS 4.0
- Type
- Secondary
- Base score
- 2.7
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- LOW
- security-advisories@github.com
- CWE-212
- Hype score
- Not currently trending
๐จ Critical patch for #Fedora42 users! CVE-2025-61594: URI credential leakage bypass CVE-2025-58767: REXML Denial-of-Service Read more: ๐ https://t.co/cyAopv8bZ3 #Security https://t.co/bH52xUKrK4
@Cezar_H_Linux
12 Nov 2025
30 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Ruby 3.4.7 ๋ฆด๋ฆฌ์ค ๋ฐํ Ruby 3.4.7์ด CVE-2025-61594 ์ทจ์ฝ์ ํด๊ฒฐ์ ์ํ uri gem ์ ๋ฐ์ดํธ ๋ฐ ๊ธฐํ ๋ฒ๊ทธ ์์ ๊ณผ ํจ๊ป ๊ณต์ ๋ฆด๋ฆฌ์ค๋์์ต๋๋ค. https://t.co/j2lPvr19zl
@rubynewskr
7 Oct 2025
8 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Ruby 3.4.7 Released https://t.co/LMrbysAVfp This release contains a uri gem update for CVE-2025-61594, along with other bug fixes. We recommend updating your uri gem version. This release has been made for the convenience of those who wish to continue using it as a default gem.
@k0kubun
7 Oct 2025
8315 Impressions
18 Retweets
76 Likes
8 Bookmarks
0 Replies
0 Quotes
Ruby: CVE-2025-61594: URI Credential Leakage Bypass previous fixes https://t.co/fTnarZbcnp #rubylang # #devtalk
@dev_talk
7 Oct 2025
5 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes