Executive brief
The oauth2 Ruby library, used by applications to handle OAuth and OpenID Connect authentication, contains a vulnerability that can leak sensitive access tokens. If a server returns a specific type of redirect (protocol-relative), the library may inadvertently send the user's secret authorization credentials to a server controlled by an attacker. This could allow an attacker to hijack user sessions or gain unauthorized access to protected data and services.
Technical details
A vulnerability exists in OAuth2::Client#request where protocol-relative URIs (e.g., //attacker.com) in the Location header of a 30x response are processed using URI#merge. Per RFC 3986, this replaces the authority of the base URL with the attacker-controlled host. Because the library recursively calls #request while preserving the original req_opts, the 'Authorization: Bearer' header is forwarded to the new host. This allows for cross-origin credential disclosure and potential SSRF. The issue is fixed in version 2.0.22 by preventing protocol-relative redirects from changing the request authority and stripping Authorization headers on cross-origin redirects.
Affected products
- ruby-oauth oauth2 >= 0.4.0, < 2.0.22
Timeline
- 2026-06-06: patched: Fix committed to repository
- 2026-06-07: advisory: GitHub Security Advisory published
- 2026-07-28: disclosed: CVE-2026-54603 published to NVD