Impact
Pay interacts with Paddle webhooks using an HMAC signature verification routine that compares a computed SHA-256 digest with the value supplied in the Paddle‑Signature header using Ruby String#==. Because the comparison is performed in linear time, an attacker can perform a timing attack by repeatedly sending requests and measuring response latencies. From these measurements the attacker can deduce matching digest prefixes and eventually reconstruct a valid HMAC, allowing the forging of a legally accepted webhook. The forged webhook is then processed by Pay::Webhooks::ProcessJob, which can modify billing state, provision paid features, record refunds, or trigger customer notifications, thereby compromising the integrity and correctness of the host application’s billing logic.
Affected Systems
The vulnerability exists in the pay‑rails:pay payments engine for Ruby on Rails 6.0 and higher. Versions prior to 11.6.2 are affected; the fix was introduced in the 11.6.2 release.
Risk and Exploitability
The CVSS score of 7.4 reflects a high‑severity risk; the EPSS score is <1%, indicating a very low but non‑zero exploitation probability, and the issue is not currently listed in the CISA KEV catalog. Based on the description, it is inferred that an unauthenticated remote attacker can submit requests to /pay/webhooks/paddle_billing and observe response timing to mount the attack. As the exploit does not require privileged access to the host or local code, the risk level remains high, especially for applications that rely on the webhook to control billing or feature access.
OpenCVE Enrichment