The gist RubyGem before 6.1.0 contains an improper certificate validation vulnerability that allows on-path attackers to intercept HTTPS traffic because http_connection in lib/gist.rb sets VERIFY_NONE. Attackers can present any certificate to read or modify GitHub API traffic, stealing OAuth tokens and login credentials to read and modify the victim's gists.

Project Subscriptions

No data.

Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Sun, 04 Oct 2026 22:45:00 +0000

Type Values Removed Values Added
Description The gist RubyGem before 6.1.0 contains an improper certificate validation vulnerability that allows on-path attackers to intercept HTTPS traffic because http_connection in lib/gist.rb sets VERIFY_NONE. Attackers can present any certificate to read or modify GitHub API traffic, stealing OAuth tokens and login credentials to read and modify the victim's gists.
Title Gist RubyGem before 6.1.0 Disabled TLS Certificate Verification
Weaknesses CWE-295
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'}

cvssV4_0

{'score': 9.1, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-04T22:31:47.153Z

Reserved: 2026-10-04T13:04:00.479Z

Link: CVE-2026-105221

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-04T23:16:59.770

Modified: 2026-10-04T23:16:59.770

Link: CVE-2026-105221

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-04T23:30:21Z

Weaknesses