CVE-2026-105221
Last modified
CVE-2026-105221 is a high-severity vulnerability rated 7.4/10 on the CVSS scale. The gist RubyGem before 6.1.0 contains an improper certificate validation vulnerability that allows on-path attackers to intercept HTTPS traffic because http_connection in lib/gist.rb sets VERIFY_NONE. Attackers can present any certificate to read or modify GitHub API traffic, stealing OAuth tokens and login credentials to read and modify the victim's gists.. EPSS estimates a 0.18% chance of exploitation in the next 30 days.
Description
The gist RubyGem before 6.1.0 contains an improper certificate validation vulnerability that allows on-path attackers to intercept HTTPS traffic because http_connection in lib/gist.rb sets VERIFY_NONE. Attackers can present any certificate to read or modify GitHub API traffic, stealing OAuth tokens and login credentials to read and modify the victim's gists.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| defunkt | gist | >= 4.0.0, < 6.1.0 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-105221?
How severe is CVE-2026-105221?
How do I fix CVE-2026-105221?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-105216go-micro before 6.0.0 contains an improper certificate valid…7.4
- CVE-2026-105217Cockpit CMS 2.12.0 before 2.14.1 disables TLS certificate ve…3.1
- CVE-2026-105218gopay before 1.5.119 disables TLS certificate verification i…7.4
- CVE-2026-105219Mammoth.js 1.3.0 before 1.12.3 contains a regular expression…7.5
- CVE-2026-10522The MemberHero WordPress plugin through 6.9 does not restri…9.8
- CVE-2026-105220Twine 2 desktop through 2.12.0 contains a cross-site scripti…7.8
- CVE-2026-105222The alexpechkarev/google-maps Laravel package through 12.16 …7.4
- CVE-2026-105223maclof kubernetes-client 0.17.0 before 0.32.0 disables TLS c…7.4
- CVE-2026-105224YesWiki before 4.6.7 contains a cross-site scripting vulnera…5.4
- CVE-2026-105225A vulnerability was identified in osCommerce osCommerce2 up …4.3
- CVE-2026-105226A security flaw has been discovered in osCommerce osCommerce…4.7
- CVE-2026-105229A weakness has been identified in kishor-23 food-waste-manag…7.3
Are you affected by CVE-2026-105221?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
