The gist RubyGem before 6.1.0 contains an improper certificate validation vulnerability that allows on-path attackers to intercept HTTPS traffic because http_connection in lib/gist.rb sets VERIFY_NONE. Attackers can present any certificate to read or modify GitHub API traffic, stealing OAuth tokens and login credentials to read and modify the victim's gists.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sun, 04 Oct 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The gist RubyGem before 6.1.0 contains an improper certificate validation vulnerability that allows on-path attackers to intercept HTTPS traffic because http_connection in lib/gist.rb sets VERIFY_NONE. Attackers can present any certificate to read or modify GitHub API traffic, stealing OAuth tokens and login credentials to read and modify the victim's gists. | |
| Title | Gist RubyGem before 6.1.0 Disabled TLS Certificate Verification | |
| Weaknesses | CWE-295 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-04T22:31:47.153Z
Reserved: 2026-10-04T13:04:00.479Z
Link: CVE-2026-105221
No data.
Status : Received
Published: 2026-10-04T23:16:59.770
Modified: 2026-10-04T23:16:59.770
Link: CVE-2026-105221
No data.
OpenCVE Enrichment
Updated: 2026-10-04T23:30:21Z
Weaknesses