Junglewise Threat Intelligence

CVE-2026-54605: Ruby OAuth cross-origin metadata disclosure in token_request

CVE-2026-54605 · Severity: high · CVSS 7.2 · Published 2026-07-28

Technologies: Ruby-Oauth Oauth. Vendors: RubyGems.

Executive brief

The Ruby OAuth library, used to handle OAuth 1.0 authentication in applications, contains a vulnerability in how it handles server redirects. If a malicious or compromised authentication server sends a redirect, the library may automatically follow it and send sensitive authentication metadata—including digital signatures and consumer keys—to an unauthorized third-party server. This could lead to the exposure of integration secrets or allow an attacker to use the application server as a proxy to reach internal network resources.

Technical details

A vulnerability exists in `OAuth::Consumer#token_request` where the library recursively follows 3xx redirects without sufficient origin validation. When a redirect is received, the library may mutate the consumer's `@http` client and `options[:site]` configuration, subsequently re-signing the OAuth request for the new destination. An attacker who can influence the redirect target of an OAuth provider can capture signed request metadata, including the `Authorization` header, `oauth_signature`, and `oauth_nonce`. Additionally, because the application server initiates the redirected request, this can be leveraged for Server-Side Request Forgery (SSRF). The issue is resolved in version 1.1.6 by introducing a redirect limit and rejecting cross-origin redirects by default.

Affected products

  • ruby-oauth oauth >= 0.5.5, < 1.1.6

Timeline

  • 2026-06-07: patched: Version 1.1.6 released
  • 2026-07-28: disclosed: CVE-2026-54605 published

References

Related threats