Junglewise Threat Intelligence

CVE-2026-33637: lostisland Faraday SSRF via protocol-relative URI objects

CVE-2026-33637 · Severity: low · CVSS 3.1 · Published 2026-05-19

Vendors: RubyGems.

Executive brief

Faraday is a popular Ruby library used by developers to make web requests. A security flaw allows an attacker to redirect web requests intended for a trusted server to a malicious one if the application uses certain input types. This could lead to the exposure of sensitive information, such as authorization tokens or private API keys, to an unauthorized third party.

Technical details

A vulnerability in Faraday::Connection#build_exclusive_url allows for a protocol-relative host override (e.g., '//attacker.com') when the request target is provided as a URI object rather than a String. This behavior bypasses a previous fix (GHSA-33mh-2634-fwr2) which only addressed String-based inputs. An attacker who can influence the path passed to request methods (like get or post) can redirect the request to an arbitrary host. Because the request is built from an existing Faraday::Connection, connection-scoped metadata—including Authorization headers and default query parameters—are forwarded to the attacker-controlled destination. The issue is fixed in version 2.14.2 (and 2.14.3).

Affected products

  • lostisland faraday >= 2.0.0, <= 2.14.1

Timeline

  • 2026-02-07: other: Original string-based SSRF (CVE-2026-25765) disclosed
  • 2026-05-18: advisory: GitHub Advisory GHSA-5rv5-xj5j-3484 published for URI object bypass
  • 2026-05-19: disclosed: CVE-2026-33637 published to NVD

References

Related threats