Description
The gist RubyGem before 6.1.0 contains an improper certificate validation vulnerability that allows on-path attackers to intercept HTTPS traffic because http_connection in lib/gist.rb sets VERIFY_NONE. Attackers can present any certificate to read or modify GitHub API traffic, stealing OAuth tokens and login credentials to read and modify the victim's gists.
Published: 2026-10-04
Score: 9.1 Critical
EPSS: n/a
KEV: No
Impact: Credential theft and API tampering via man‑in‑the‑middle
Action: Immediate Patch
AI Analysis

Impact

The gist RubyGem prior to version 6.1.0 mistakenly sets the SSL certificate verification mode to VERIFY_NONE, allowing an attacker on the network path to substitute any TLS certificate. This malicious certificate can be used to intercept, read, or modify HTTPS traffic to the GitHub API, enabling the theft of OAuth tokens and login credentials and the alteration of the victim’s gists. The vulnerability is a classic example of improper certificate validation, classified as CWE‑295, and results in a severe breach of confidentiality, integrity, and potentially availability.

Affected Systems

All installations of the defunkt:gist RubyGem older than 6.1.0 are affected, including source versions such as 6.0.0. Users must check the gem version in their applications or development environments and verify whether it falls under this scope.

Risk and Exploitability

With a CVSS score of 9.1, the vulnerability is considered Critical. The EPSS score is not available, but the lack of a CISA KEV listing does not diminish the inherent danger; an on‑path attacker can exploit the flaw without additional prerequisites. The affected code path is exposed whenever HTTP requests are made to GitHub via the gem, so any application that relies on the gem is at risk. The primary attack vector is a network‑level attacker in the traffic path, able to present an arbitrary certificate and intercept traffic. This poses an immediate threat to users who authenticate via GitHub API calls that could be replayed or tampered with.

Generated by OpenCVE AI on October 4, 2026 at 23:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the defunkt:gist gem to version 6.1.0 or later to re‑enable proper TLS certificate verification.
  • If upgrading is not immediately feasible, replace the lib/gist.rb file’s http_connection block to enforce certificate verification, for example by setting ssl_context.verify_mode to VERIFY_PEER.
  • Configure your network to detect and block TLS interception or use a trusted outbound proxy that performs strict certificate validation.

Generated by OpenCVE AI on October 4, 2026 at 23:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 04 Oct 2026 22:45:00 +0000

Type Values Removed Values Added
Description The gist RubyGem before 6.1.0 contains an improper certificate validation vulnerability that allows on-path attackers to intercept HTTPS traffic because http_connection in lib/gist.rb sets VERIFY_NONE. Attackers can present any certificate to read or modify GitHub API traffic, stealing OAuth tokens and login credentials to read and modify the victim's gists.
Title Gist RubyGem before 6.1.0 Disabled TLS Certificate Verification
Weaknesses CWE-295
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'}

cvssV4_0

{'score': 9.1, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-04T22:31:47.153Z

Reserved: 2026-10-04T13:04:00.479Z

Link: CVE-2026-105221

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-04T23:16:59.770

Modified: 2026-10-04T23:16:59.770

Link: CVE-2026-105221

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-04T23:30:21Z

Weaknesses
  • CWE-295

    Improper Certificate Validation