CVE-2026-25765 | lostisland faraday up to 2.14.0 URL connection.rb build_exclusive_url server-side request forgery (GHSA-33mh-2634-fwr2 / Nessus ID 298451)
A vulnerability was found in lostisland faraday up to 2.14.0. It has been classified as critical. Affected by this issue is the function build_exclusive_url in the library lib/faraday/connection.rb of the component URL Handler. This manipulation causes server-side request forgery.
The identification of this vulnerability is CVE-2026-25765. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is recommended.