[CVE-2026-25765] How Neo found an SSRF vulnerability in Faraday, and why it matters for every team that ships code
projectdiscovery.io | vulnerability | CVE-2026-25765 | #ai-security | #bug-bounty | #supply-chain | #ruby | #vulnerability-discovery | #ssrf | #neo | #faraday | #cve-2026-25765
Summary
Neo independently found an SSRF in Faraday, the popular Ruby HTTP client: a URL like //evil.com overrides the destination host. Tracked as CVE-2026-25765 (CVSS 5.8), fixed in Faraday 2.14.1.
- CVE
- CVE-2026-25765
- Published
- Collected
Skip to content