
CVE-2026-105221 The gist RubyGem before 6.1.0 contains an improper certificate validation vulnerability that allows on-path attackers to intercept HTTPS traffic because http_connec… https://www.cve.org/CVERecord?id=CVE-2026-105221
Signal is active with 2 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
The gist RubyGem before 6.1.0 contains an improper certificate validation vulnerability that allows on-path attackers to intercept HTTPS traffic because http_connection in lib/gist.rb sets VERIFY_NONE. Attackers can present any certificate to read or modify GitHub API traffic, stealing OAuth tokens and login credentials to read and modify the victim's gists.
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
NONE
Momentum
NONE

CVE-2026-105221 The gist RubyGem before 6.1.0 contains an improper certificate validation vulnerability that allows on-path attackers to intercept HTTPS traffic because http_connec… https://www.cve.org/CVERecord?id=CVE-2026-105221

Η κρίσιμη ευπάθεια CVE-2026-105221 στο RubyGem Gist https://www.secnews.gr/737858/cve-2026-105221-rubygem-gist-tls/?fsp_sid=16677