CVE-2025-61594

URI is a module providing classes to handle Uniform Resource Identifiers. In versions prior to 0.12.5, 0.13.3, and 1.0.4, a bypass exists for the fix to CVE-2025-27221 that can expose user credentials. When using the `+` operator to combine URIs, sensitive information like passwords from the original URI can be leaked, violating RFC3986 and making applications vulnerable to credential exposure. Versions 0.12.5, 0.13.3, and 1.0.4 fix the issue.
CVSS

No CVSS.

Configurations

No configuration.

History

30 Dec 2025, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-30 21:15

Updated : 2025-12-31 20:42


NVD link : CVE-2025-61594

Mitre link : CVE-2025-61594

CVE.ORG link : CVE-2025-61594


JSON object : View

Products Affected

No product.

CWE
CWE-212

Improper Removal of Sensitive Information Before Storage or Transfer