GHSA-hww2-5g85-429m

    Dashboard / Vulnerabilities / GHSA-hww2-5g85-429m

    GHSA-hww2-5g85-429m

    Published: 29 Jun 2023Last Modified: 10 Sept 2026

    Summary: URI gem has ReDoS vulnerability

    Details: A ReDoS issue was discovered in the URI component before 0.12.2 for Ruby. The URI parser mishandles invalid URLs that have specific characters. There is an increase in execution time for parsing strings to URI objects with `rfc2396_parser.rb` and `rfc3986_parser.rb`. NOTE: this issue exists becuse of an incomplete fix for CVE-2023-28755. Version 0.10.3 is also a fixed version. [The Ruby advisory recommends](https://www.ruby-lang.org/en/news/2023/06/29/redos-in-uri-CVE-2023-36617/) updating the uri gem to 0.12.2. In order to ensure compatibility with the bundled version in older Ruby series, you may update as follows instead: - For Ruby 3.0: Update to uri 0.10.3 - For Ruby 3.1 and 3.2: Update to uri 0.12.2. You can use gem update uri to update it. If you are using bundler, please add gem `uri`, `>= 0.12.2` (or other version mentioned above) to your Gemfile.

    Affected packages

    Package

    Name: uri

    Purl: pkg:gem/uri

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0.10.1
    Fixed -0.10.3

    Affected versions

    0.10.1
    0.10.2

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-hww2-5g85-429m | CVE-DB