Improper Certificate Validation in Gist RubyGem by Defunkt
CVE-2026-105221

9.1CRITICAL

Key Information:

Vendor

Defunkt

Status
Vendor
CVE Published:
4 October 2026

What is CVE-2026-105221?

The Gist RubyGem, used for interfacing with GitHub's API, contains a vulnerability due to improper certificate validation mechanisms. Specifically, versions prior to 6.1.0 fail to verify SSL certificates correctly, allowing attackers to intercept HTTPS traffic by setting the VERIFY_NONE option. This weakness enables on-path attackers to present fraudulent certificates for reading or modifying traffic destined for the GitHub API. As a result, sensitive information such as OAuth tokens and user credentials can be compromised, leading to unauthorized access to and manipulation of users' gists. It is critical for users of Gist RubyGem to upgrade to version 6.1.0 or later to mitigate this risk.

Affected Version(s)

gist 4.0.0 < 6.1.0

References

CVSS V4

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Siyang Wu
.