OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-105221

HIGH · CVSS 7.4 EPSS 0.18% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-10-04 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

The gist RubyGem prior to version 6.1.0 is vulnerable due to improper certificate validation, allowing on-path attackers to intercept HTTPS traffic by setting VERIFY_NONE in the http_connection method. This flaw enables attackers to present fraudulent certificates, potentially leading to the theft of OAuth tokens and login credentials, which can compromise user gists. Developers and organizations using the affected RubyGem should prioritize upgrading to version 6.1.0 or later to mitigate this high-severity risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-105221
Severity
HIGH
CVSS
7.4
EPSS
0.18%
GitHub

Original NVD Description

The gist RubyGem before 6.1.0 contains an improper certificate validation vulnerability that allows on-path attackers to intercept HTTPS traffic because http_connection in lib/gist.rb sets VERIFY_NONE. Attackers can present any certificate to read or modify GitHub API traffic, stealing OAuth tokens and login credentials to read and modify the victim's gists.