CVE-2025-27221 | URI Gem up to 0.11.2/0.12.3/0.13.1/1.0.2 on Ruby URI.join/URI#merge/URI#+ improper removal of sensitive information before storage or transfer (EUVD-2025-5508 / Nessus ID 232079)
A vulnerability was found in URI Gem up to 0.11.2/0.12.3/0.13.1/1.0.2 on Ruby. It has been rated as problematic. Affected by this issue is the function URI.join/URI#merge/URI#+. The manipulation leads to improper removal of sensitive information before storage or transfer.
This vulnerability is handled as CVE-2025-27221. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.