CVE-2026-105221 Exposes GitHub OAuth Tokens via TLS Flaw
Article Content
- •CVE-2026-105221 allows MITM attacks on GitHub OAuth tokens.
- •The vulnerability affects gist RubyGem versions before 6.1.0.
- •Immediate patching is required to prevent credential exposure.
A vulnerability identified as CVE-2026-105221 in the gist RubyGem allows on-path attackers to intercept HTTPS traffic due to improper certificate validation. The flaw, present in versions before 6.1.0, hardcodes verify_mode to VERIFY_NONE, exposing GitHub OAuth tokens to man-in-the-middle (MITM) attacks. This could enable unauthorized access to users' gists and GitHub accounts. The vulnerability has a CVSS score of 9.1, classifying it as. Affected users are those running Ruby scripts or automation tools that utilize this gem, particularly in untrusted network environments. The flaw was disclosed on October 4, 2026, and a patch is available. Immediate action is recommended to mitigate risks associated with exposed tokens.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track CVE-2026-105221 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
Which versions of the gist RubyGem are affected?
What is the risk of this vulnerability?
What should I do to mitigate this issue?
Continue Reading
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…
Critical Authentication Bypass in Cisco Catalyst SD-WAN Manager Exploited On September 30, 2026, Cisco disclosed a critical vulnerability (CVE-2026-76504) in the Catalyst SD-WAN Manager that allows unauthenticated remote attackers to bypass authentication and gain admin-level access to the system. This flaw stems from improper handling of URI encoding in HTTP requests, enabling attackers to…