Skip to content
CVE-2026-105221 Exposes GitHub OAuth Tokens via TLS Flaw

CVE-2026-105221 Exposes GitHub OAuth Tokens via TLS Flaw

First seen 5 Oct 2026, 08:04 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 5, 2026 at 08:05 UTC
  • •CVE-2026-105221 allows MITM attacks on GitHub OAuth tokens.
  • •The vulnerability affects gist RubyGem versions before 6.1.0.
  • •Immediate patching is required to prevent credential exposure.

A vulnerability identified as CVE-2026-105221 in the gist RubyGem allows on-path attackers to intercept HTTPS traffic due to improper certificate validation. The flaw, present in versions before 6.1.0, hardcodes verify_mode to VERIFY_NONE, exposing GitHub OAuth tokens to man-in-the-middle (MITM) attacks. This could enable unauthorized access to users' gists and GitHub accounts. The vulnerability has a CVSS score of 9.1, classifying it as. Affected users are those running Ruby scripts or automation tools that utilize this gem, particularly in untrusted network environments. The flaw was disclosed on October 4, 2026, and a patch is available. Immediate action is recommended to mitigate risks associated with exposed tokens.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Timeline

2026-10-04
CVE-2026-105221 published
The vulnerability was disclosed with a CVSS score of 9.1, indicating critical severity.
Redpacketsecurity

More articles in this cluster (3)

Following this threat?

Track CVE-2026-105221 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Which versions of the gist RubyGem are affected?
Versions of the gist RubyGem before 6.1.0 are affected by this vulnerability.
What is the risk of this vulnerability?
The risk includes potential unauthorized access to GitHub accounts and gists due to exposed OAuth tokens.
What should I do to mitigate this issue?
Upgrade to gist RubyGem version 6.1.0 or later and revoke any potentially exposed tokens.