GEM · JULY 2026 · CONFIRMED

OAuth Ruby Gem <=1.1.5: Cross-Origin Signed Request Metadata Exposure

GHSA-PRQ8-7WVH-44QHSeverity: HIGH

The OAuth gem for Ruby <=1.1.5 can expose signed request metadata due to cross-origin token-request redirects. Upgrade to oauth v1.1.6 or later to mitigate.

What happened

The OAuth gem for Ruby, versions <=1.1.5, has a vulnerability (GHSA-PRQ8-7WVH-44QH) where cross-origin token-request redirects can expose signed request metadata. This can lead to cross-origin signed-request disclosure. The recommended action is to upgrade to oauth v1.1.6 or later to mitigate the exposure of signed request metadata. For more details, consult the primary sources: [GHSA-3735-5339-xfwx], [GHSA-prq8-7wvh-44qh], and [GHSA-pp92-crg2-gfv9].

Additionally, Poweradmin has a separate Host Header Injection vulnerability (CVE-2026-54588) in OIDC redirect_uri, SAML ACS/SLO URL, and Logout Redirect Construction. This is tracked under [GHSA-3735-5339-xfwx]. The OAuth2 gem also has a vulnerability (GHSA-pp92-crg2-gfv9) where protocol-relative redirect Location overrides authority, leaking bearer Authorization to attacker host.

For the most accurate and detailed information, please refer to the primary sources provided. If any details are unclear or missing, the primary sources should be consulted for further clarification.

How 0Day mitigates this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If oauth is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Join the 0Day waitlist →

← Back to all threats