PatchSiren

ruby-oauth CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH ruby-oauth CVE published 2026-07-28

CVE-2026-54605

CVE-2026-54605 is a vulnerability in the OAuth Ruby wrapper for the OAuth 1.0 and 1.0a protocols. Affected versions from 0.5.5 to 1.1.5 allow an attacker to mutate the consumer's configuration and expose signed OAuth request metadata by recursively following redirects. This issue is fixed in version 1.1.6. The vulnerability allows an attacker to expose sensitive information, including the Authorization he [truncated]

HIGH ruby-oauth CVE published 2026-07-28

CVE-2026-54603

A vulnerability in the OAuth2 Ruby wrapper for OAuth 2.0 and 2.1 authorization frameworks, including OpenID Connect (OIDC), allows an attacker to leak bearer Authorization headers by exploiting a protocol-relative redirect Location in OAuth2::Client#request. This issue affects versions from 0.4.0 to 2.0.21 and is fixed in version 2.0.22. The vulnerability has a high CVSS score of 8.6, indicating a signifi [truncated]