CRITICAL
defunkt
CVE published 2026-10-04
CVE-2026-105221
The gist RubyGem before 6.1.0 contains an improper certificate validation vulnerability. This CVE record was published on 2026-10-04T23:16:59.770Z and has not been modified since then. The NVD entry is currently Received. The vulnerability allows on-path attackers to intercept HTTPS traffic, potentially stealing OAuth tokens and login credentials, and modifying GitHub API traffic. Defenders should assess [truncated]