oauth
RubyGems2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting oauthpage 1 of 1
- CVE-2016-11086HIGHCVSS 7.4EG 7.4✓ Fixed in 0.5.52020-09-24
vulnerable: 0.1.1 ... 0.5.4 (28 versions)
lib/oauth/consumer.rb in the oauth-ruby gem through 0.5.4 for Ruby does not verify server X.509 certificates if a certificate bundle cannot be found, which allows man-in-the-middle attackers to spoof servers and obtain sensitive informatio…
- CVE-2026-54605HIGHCVSS 7.2EG 7.2✓ Fixed in 1.1.62026-07-28
vulnerable: 0.5.10 ... 1.1.5 (22 versions)
OAuth is a Ruby wrapper for the OAuth 1.0 and 1.0a protocols, providing clients and servers. From 0.5.5 to 1.1.5, OAuth::Consumer#token_request parses the raw Location header of a 300 to 399 redirect returned by the OAuth server and follow…
Check whether oauth is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for oauth CVEs against the assets you own.
Start Free Scan →