What is CVE-2026-54605?
CVE-2026-54605 is an open redirect vulnerability in the Ruby OAuth library affecting versions 0.5.5 to 1.1.5 where `OAuth::Consumer#token_request` blindly follows the `Location` header of a redirect, potentially mutating the consumer’s configuration. Users are advised to immediately upgrade to version 1.1.6 or later.
Azərbaycanca: CVE-2026-54605 Ruby üçün OAuth kitabxanasında 0.5.5-dən 1.1.5-ə qədər olan versiyalara təsir edən `OAuth::Consumer#token_request` funksiyasında açıq yönləndirmə (open redirect) zəifliyidir. Təhlükə ondan ibarətdir ki, funksiya OAuth serverindən gələn `Location` başlığını yoxlamadan izləyir və bu, istehlakçının konfiqurasiyasını mutasiya edə bilər. İstifadəçilərə təcili olaraq 1.1.6 və ya daha yuxarı versiyaya yeniləmək tövsiyə olunur.
FAQ2
Which versions of the Ruby OAuth library are affected by CVE-2026-54605?
This vulnerability affects versions 0.5.5 to 1.1.5 of the Ruby OAuth library.
What action is recommended to mitigate CVE-2026-54605?
Users are advised to immediately upgrade to version 1.1.6 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.