Description
Pay is a payments engine for Ruby on Rails 6.0 and higher. Prior to 11.6.2, Pay::Webhooks::PaddleBillingController#valid_signature? in app/controllers/pay/webhooks/paddle_billing_controller.rb compares the computed 64-character SHA-256 HMAC with the attacker-controlled h1 token from the Paddle-Signature header using Ruby String#==. An unauthenticated remote attacker who can repeatedly submit requests to /pay/webhooks/paddle_billing and obtain sufficiently precise timing measurements can infer matching digest prefixes and recover a valid signature. A forged accepted webhook is enqueued through Pay::Webhooks::ProcessJob and can cause a host application to update billing state, provision paid features, record refunds, or trigger customer notifications. This issue is fixed in version 11.6.2.
Published: 2026-09-14
Score: 7.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Billing Actions
Action: Apply Patch Now
AI Analysis

Impact

Pay interacts with Paddle webhooks using an HMAC signature verification routine that compares a computed SHA-256 digest with the value supplied in the Paddle‑Signature header using Ruby String#==. Because the comparison is performed in linear time, an attacker can perform a timing attack by repeatedly sending requests and measuring response latencies. From these measurements the attacker can deduce matching digest prefixes and eventually reconstruct a valid HMAC, allowing the forging of a legally accepted webhook. The forged webhook is then processed by Pay::Webhooks::ProcessJob, which can modify billing state, provision paid features, record refunds, or trigger customer notifications, thereby compromising the integrity and correctness of the host application’s billing logic.

Affected Systems

The vulnerability exists in the pay‑rails:pay payments engine for Ruby on Rails 6.0 and higher. Versions prior to 11.6.2 are affected; the fix was introduced in the 11.6.2 release.

Risk and Exploitability

The CVSS score of 7.4 reflects a high‑severity risk; the EPSS score is <1%, indicating a very low but non‑zero exploitation probability, and the issue is not currently listed in the CISA KEV catalog. Based on the description, it is inferred that an unauthenticated remote attacker can submit requests to /pay/webhooks/paddle_billing and observe response timing to mount the attack. As the exploit does not require privileged access to the host or local code, the risk level remains high, especially for applications that rely on the webhook to control billing or feature access.

Generated by OpenCVE AI on September 21, 2026 at 00:27 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the pay‑rails:pay gem to version 11.6.2 or later
  • Restart the application to apply the updated gem
  • Verify webhook functionality and monitor logs for unexpected billing activity

Generated by OpenCVE AI on September 21, 2026 at 00:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Pay-rails
Pay-rails pay
Vendors & Products Pay-rails
Pay-rails pay

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description Pay is a payments engine for Ruby on Rails 6.0 and higher. Prior to 11.6.2, Pay::Webhooks::PaddleBillingController#valid_signature? in app/controllers/pay/webhooks/paddle_billing_controller.rb compares the computed 64-character SHA-256 HMAC with the attacker-controlled h1 token from the Paddle-Signature header using Ruby String#==. An unauthenticated remote attacker who can repeatedly submit requests to /pay/webhooks/paddle_billing and obtain sufficiently precise timing measurements can infer matching digest prefixes and recover a valid signature. A forged accepted webhook is enqueued through Pay::Webhooks::ProcessJob and can cause a host application to update billing state, provision paid features, record refunds, or trigger customer notifications. This issue is fixed in version 11.6.2.
Title pay-rails/pay: non-constant-time HMAC comparison in Paddle Billing webhook signature verifier
Weaknesses CWE-208
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-14T18:57:30.947Z

Reserved: 2026-08-04T21:48:08.613Z

Link: CVE-2026-70658

cve-icon Vulnrichment

Updated: 2026-09-14T18:57:05.417Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T18:19:45.213

Modified: 2026-09-30T19:09:53.523

Link: CVE-2026-70658

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T00:30:06Z

Weaknesses
  • CWE-208

    Observable Timing Discrepancy