


Perceptive Security
SOC/SIEM Consultancy

OAuth2 is a Ruby wrapper for the OAuth 2.0 and 2.1 authorization frameworks, including OpenID Connect (OIDC). From 0.4.0 to 2.0.21, a protocol-relative redirect…
Published:
28 juli 2026 om 00:00:00
Alert date:
28 juli 2026 om 20:03:14
Source:
nvd.nist.gov
Identity & Access, Web Technologies, Supply Chain & Dependencies
A vulnerability exists in the OAuth2 Ruby gem (versions 0.4.0 through 2.0.21) that allows credential leakage via protocol-relative redirect manipulation. When a malicious or attacker-controlled server returns a protocol-relative URL in the redirect Location header, the OAuth2::Client#request method overrides the original request authority. This causes the bearer Authorization header containing the credential to be sent to the attacker-controlled host. The vulnerability affects applications using OAuth 2.0, OAuth 2.1, and OpenID Connect (OIDC) flows implemented through this gem. The issue has been patched in version 2.0.22 of the oauth2 Ruby gem. Users are strongly advised to upgrade immediately to prevent credential theft and potential account compromise.
Technical details
Mitigation steps:
Affected products:
oauth2 Ruby gem (versions 0.4.0 to 2.0.21)
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-54603
https://github.com/ruby-oauth/oauth2/commit/0f0a474f1b38453e119e660c2daca742d4378ce9
https://github.com/ruby-oauth/oauth2/releases/tag/v2.0.22
https://github.com/ruby-oauth/oauth2/security/advisories/GHSA-pp92-crg2-gfv9
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
