Junglewise Threat Intelligence

CVE-2026-54603: ruby-oauth oauth2 credential leakage via protocol-relative redirect

CVE-2026-54603 · Severity: high · CVSS 8.6 · Published 2026-07-28

Vendors: RubyGems.

Executive brief

The oauth2 Ruby library, used by applications to handle OAuth and OpenID Connect authentication, contains a vulnerability that can leak sensitive access tokens. If a server returns a specific type of redirect (protocol-relative), the library may inadvertently send the user's secret authorization credentials to a server controlled by an attacker. This could allow an attacker to hijack user sessions or gain unauthorized access to protected data and services.

Technical details

A vulnerability exists in OAuth2::Client#request where protocol-relative URIs (e.g., //attacker.com) in the Location header of a 30x response are processed using URI#merge. Per RFC 3986, this replaces the authority of the base URL with the attacker-controlled host. Because the library recursively calls #request while preserving the original req_opts, the 'Authorization: Bearer' header is forwarded to the new host. This allows for cross-origin credential disclosure and potential SSRF. The issue is fixed in version 2.0.22 by preventing protocol-relative redirects from changing the request authority and stripping Authorization headers on cross-origin redirects.

Affected products

  • ruby-oauth oauth2 >= 0.4.0, < 2.0.22

Timeline

  • 2026-06-06: patched: Fix committed to repository
  • 2026-06-07: advisory: GitHub Security Advisory published
  • 2026-07-28: disclosed: CVE-2026-54603 published to NVD

References