top of page
perceptive_background_267k.jpg

OAuth2 is a Ruby wrapper for the OAuth 2.0 and 2.1 authorization frameworks, including OpenID Connect (OIDC). From 0.4.0 to 2.0.21, a protocol-relative redirect…

Published:

28 juli 2026 om 00:00:00

Alert date:

28 juli 2026 om 20:03:14

Source:

nvd.nist.gov

Click to open the original link from this advisory

Identity & Access, Web Technologies, Supply Chain & Dependencies

A vulnerability exists in the OAuth2 Ruby gem (versions 0.4.0 through 2.0.21) that allows credential leakage via protocol-relative redirect manipulation. When a malicious or attacker-controlled server returns a protocol-relative URL in the redirect Location header, the OAuth2::Client#request method overrides the original request authority. This causes the bearer Authorization header containing the credential to be sent to the attacker-controlled host. The vulnerability affects applications using OAuth 2.0, OAuth 2.1, and OpenID Connect (OIDC) flows implemented through this gem. The issue has been patched in version 2.0.22 of the oauth2 Ruby gem. Users are strongly advised to upgrade immediately to prevent credential theft and potential account compromise.

Technical details

Mitigation steps:

Affected products:

oauth2 Ruby gem (versions 0.4.0 to 2.0.21)

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page