Improper Certificate Validation in Gist RubyGem by Defunkt
CVE-2026-105221
9.1CRITICAL
What is CVE-2026-105221?
The Gist RubyGem, used for interfacing with GitHub's API, contains a vulnerability due to improper certificate validation mechanisms. Specifically, versions prior to 6.1.0 fail to verify SSL certificates correctly, allowing attackers to intercept HTTPS traffic by setting the VERIFY_NONE option. This weakness enables on-path attackers to present fraudulent certificates for reading or modifying traffic destined for the GitHub API. As a result, sensitive information such as OAuth tokens and user credentials can be compromised, leading to unauthorized access to and manipulation of users' gists. It is critical for users of Gist RubyGem to upgrade to version 6.1.0 or later to mitigate this risk.
Affected Version(s)
gist 4.0.0 < 6.1.0
