EXECUTIVE SUMMARY:
CVE-2026-54603 with a CVSS score of 8.6 is a high-severity vulnerability affecting the rubygems/oauth2 library. This flaw occurs when the OAuth2::Client#request method processes a protocol-relative redirect location, which incorrectly overrides the original request authority during URL merging. An attacker can exploit this issue by influencing the authorization server to return a redirect header starting with "//", causing the client to send a request to an attacker-controlled host while preserving the sensitive Authorization header. Consequently, the attacker gains the ability to steal bearer access tokens and potentially perform Server-Side Request Forgery (SSRF) against internal network resources. The business impact includes severe confidentiality breaches and unauthorized system access, as malicious actors can hijack user sessions or access internal infrastructure. Exploitation requires that the application utilize the vulnerable client methods and that the attacker can manipulate the redirect target, such as through a compromised endpoint, malicious tenant, or open redirect vulnerability.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY:
CVE-2026-54603 with a CVSS score of 8.6 is a high-severity vulnerability affecting the rubygems/oauth2 library. This flaw occurs when the OAuth2::Client#request method processes a protocol-relative redirect location, which incorrectly overrides the original request authority during URL merging. An attacker can exploit this issue by influencing the authorization server to return a redirect header starting with "//", causing the client to send a request to an attacker-controlled host while preserving the sensitive Authorization header. Consequently, the attacker gains the ability to steal bearer access tokens and potentially perform Server-Side Request Forgery (SSRF) against internal network resources. The business impact includes severe confidentiality breaches and unauthorized system access, as malicious actors can hijack user sessions or access internal infrastructure. Exploitation requires that the application utilize the vulnerable client methods and that the attacker can manipulate the redirect target, such as through a compromised endpoint, malicious tenant, or open redirect vulnerability.[emaillocker id="1283"]
RECOMMENDATION:
REFERENCES:
The following reports contain further technical details:
[/emaillocker]