High severity8.6NVD Advisory· Published Jul 28, 2026· Updated Sep 9, 2026
CVE-2026-54603
CVE-2026-54603
Description
OAuth2 is a Ruby wrapper for the OAuth 2.0 and 2.1 authorization frameworks, including OpenID Connect (OIDC). From 0.4.0 to 2.0.21, a protocol-relative redirect Location returned to OAuth2::Client#request overrides the request authority, so the bearer Authorization header is sent to an attacker-controlled host, leaking the credential. This issue is fixed in version 2.0.22.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
oauth2RubyGems | >= 0.4.0, < 2.0.22 | 2.0.22 |
Affected products
11- Range: 0.4.0 to 2.0.21
- osv-coords10 versionspkg:apk/chainguard/gitlab-rails-ce-18.6pkg:apk/chainguard/ruby3.2-oauth2pkg:apk/chainguard/ruby3.3-oauth2pkg:apk/chainguard/ruby3.4-oauth2pkg:apk/chainguard/ruby4.0-oauth2pkg:apk/wolfi/ruby3.2-oauth2pkg:apk/wolfi/ruby3.3-oauth2pkg:apk/wolfi/ruby3.4-oauth2pkg:apk/wolfi/ruby4.0-oauth2pkg:apk/chainguard/gitlab-rails-ce-fips-18.9
< 18.6.8-r5+ 9 more
- (no CPE)range: < 18.6.8-r5
- (no CPE)range: < 2.0.22-r0
- (no CPE)range: < 2.0.22-r0
- (no CPE)range: < 2.0.22-r0
- (no CPE)range: < 2.0.22-r1
- (no CPE)range: < 2.0.22-r0
- (no CPE)range: < 2.0.22-r0
- (no CPE)range: < 2.0.22-r0
- (no CPE)range: < 2.0.22-r1
- (no CPE)range: < 18.9.8-r4
Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.