What is CVE-2026-54603?
CVE-2026-54603 is a vulnerability in the Ruby OAuth2 library where a protocol-relative redirect in `Location` header allows leaking of Bearer tokens to an attacker-controlled server via the `OAuth2::Client#request` method. Affected versions range from 0.4.0 to 2.0.21. Users must update the library immediately and strictly validate redirect URIs.
Azərbaycanca: CVE-2026-54603, Ruby üçün OAuth2 kitabxanasında `OAuth2::Client#request` funksiyası vasitəsilə etibarsız redirect zamanı protokol-nisbi `Location` başlığı səbəbindən Bearer token-in təcavüzkarın serverinə sızmasına yol açan zəiflikdir. Bu, 0.4.0-dan 2.0.21-ə qədər versiyaları təsir edir. İstifadəçilər dərhal kitabxananı yeniləməli və redirect URI-lərini ciddi şəkildə yoxlamalıdır.
FAQ1
Which version of the Ruby OAuth2 library should be upgraded to in order to mitigate CVE-2026-54603?
Since versions 0.4.0 to 2.0.21 are affected, users must update to the latest version where this vulnerability is patched, and strictly validate redirect URIs.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.