Executive brief
The Ruby OAuth library, used to handle OAuth 1.0 authentication in applications, contains a vulnerability in how it handles server redirects. If a malicious or compromised authentication server sends a redirect, the library may automatically follow it and send sensitive authentication metadata—including digital signatures and consumer keys—to an unauthorized third-party server. This could lead to the exposure of integration secrets or allow an attacker to use the application server as a proxy to reach internal network resources.
Technical details
A vulnerability exists in `OAuth::Consumer#token_request` where the library recursively follows 3xx redirects without sufficient origin validation. When a redirect is received, the library may mutate the consumer's `@http` client and `options[:site]` configuration, subsequently re-signing the OAuth request for the new destination. An attacker who can influence the redirect target of an OAuth provider can capture signed request metadata, including the `Authorization` header, `oauth_signature`, and `oauth_nonce`. Additionally, because the application server initiates the redirected request, this can be leveraged for Server-Side Request Forgery (SSRF). The issue is resolved in version 1.1.6 by introducing a redirect limit and rejecting cross-origin redirects by default.
Affected products
- ruby-oauth oauth >= 0.5.5, < 1.1.6
Timeline
- 2026-06-07: patched: Version 1.1.6 released
- 2026-07-28: disclosed: CVE-2026-54605 published