httparty is an API tool. In versions 0.23.2 and prior, httparty is vulnerable to SSRF. This issue can pose a risk of leaking API keys, and it can also allow third parties to issue requests to internal servers. This issue has been patched via commit 0529bcd.
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-hm5p-x4rq-38w4 httparty Has Potential SSRF Vulnerability That Leads to API Key Leakage
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 23 Dec 2025 23:15:00 +0000

Type Values Removed Values Added
Description httparty is an API tool. In versions 0.23.2 and prior, httparty is vulnerable to SSRF. This issue can pose a risk of leaking API keys, and it can also allow third parties to issue requests to internal servers. This issue has been patched via commit 0529bcd.
Title httparty Has Potential SSRF Vulnerability That Leads to API Key Leakage
Weaknesses CWE-918
References
Metrics cvssV4_0

{'score': 7.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:P'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-12-23T22:59:04.201Z

Reserved: 2025-12-23T17:11:35.076Z

Link: CVE-2025-68696

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-12-23T23:15:45.627

Modified: 2025-12-23T23:15:45.627

Link: CVE-2025-68696

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses