OAuth2 Vulnerability in Ruby Wrapper Affects User Credentials
CVE-2026-54603

8.6HIGH

Key Information:

Vendor

Ruby-oauth

Status
Vendor
CVE Published:
28 July 2026

What is CVE-2026-54603?

A vulnerability in the OAuth2 Ruby wrapper allows attackers to leverage protocol-relative redirects, leading to the leakage of the bearer Authorization header to malicious hosts. This compromises user credentials and could grant unauthorized access. The issue has been resolved in version 2.0.22, which users should upgrade to immediately.

Affected Version(s)

oauth2 >= 0.4.0, < 2.0.22

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.