1.
projectdiscovery.io | vulnerability | | original ↗ | #ai-security | #bug-bounty | #supply-chain | #ruby
Neo independently found an SSRF in Faraday, the popular Ruby HTTP client: a URL like //evil.com overrides the destination host. Tracked as CVE-2026-25765 (CVSS 5.8), fixed in Faraday 2.14.1.
Skip to content