CVE-2025-68696: httparty Has Potential SSRF Vulnerability That Leads to API Key Leakage
(updated )
There may be an SSRF vulnerability in httparty. This issue can pose a risk of leaking API keys, and it can also allow third parties to issue requests to internal servers.
References
- github.com/advisories/GHSA-hm5p-x4rq-38w4
- github.com/jnunemaker/httparty
- github.com/jnunemaker/httparty/commit/0529bcd6309c9fd9bfdd50ae211843b10054c240
- github.com/jnunemaker/httparty/security/advisories/GHSA-hm5p-x4rq-38w4
- github.com/rubysec/ruby-advisory-db/blob/master/gems/httparty/CVE-2025-68696.yml
- nvd.nist.gov/vuln/detail/CVE-2025-68696
Code Behaviors & Features
Detect and mitigate CVE-2025-68696 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →