A high-severity flaw tracked as CVE-2026-54603 affects the Ruby oauth2 library and can leak bearer credentials during redirect handling. In versions 0.4.0 through 2.0.21, a protocol-relative Location header processed by OAuth2::Client#request can override the intended authority, causing the Authorization header to be forwarded to an attacker-controlled host. The issue is classified under CWE-200 and CWE-601 and carries a CVSS 3.1 vector of AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N.
The maintainers released oauth2 v2.0.22 with a fix that prevents protocol-relative redirects from changing request authority and strips Authorization headers from cross-origin redirects. A related GitHub commit shows added tests confirming that credentials remain on same-origin redirects, are removed on cross-origin redirects, and that cross-origin redirects can still proceed when no credential headers are present. GitHub also published a security advisory for the issue, and users are urged to upgrade to the patched release.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
On 2026-06-07, ruby-oauth released version 2.0.22 containing the security fix for advisory GHSA-pp92-crg2-gfv9. The release notes state it prevents protocol-relative redirects from changing request authority and removes Authorization headers from cross-origin redirects.
On 2026-06-07, a commit to ruby-oauth/oauth2 changed redirect handling so protocol-relative Location headers could not change request authority and stripped Authorization headers on cross-origin redirects. The patch also added tests covering same-origin and cross-origin redirect behavior.
CVE-2026-54603 was disclosed as affecting ruby-oauth oauth2 versions 0.4.0 through 2.0.21, where a protocol-relative redirect could override the intended authority and leak bearer Authorization headers to an attacker-controlled host. The CVE record notes the issue is fixed in version 2.0.22.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvereports.com
Open sourcegithub.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.