Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

[CVE-2026-25765] How Neo found an SSRF vulnerability in Faraday, and why it matters for every team that ships code

Summary

Neo independently found an SSRF in Faraday, the popular Ruby HTTP client: a URL like //evil.com overrides the destination host. Tracked as CVE-2026-25765 (CVSS 5.8), fixed in Faraday 2.14.1.
CVE
CVE-2026-25765
Published
Collected

original ↗