<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 15:41:38 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-342162</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-342162</link>
      <description>EUVD-2026-342162</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-342162</guid>
    </item>
    <item>
      <title>fkie_cve-2026-54605</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-54605</link>
      <description>&lt;p&gt;OAuth is a Ruby wrapper for the OAuth 1.0 and 1.0a protocols, providing clients and servers. From 0.5.5 to 1.1.5, OAuth::Consumer#token_request parses the raw Location header of a 300 to 399 redirect returned by the OAuth server and follows the redirect recursively, which can mutate the consumer&amp;#39;s configuration and expose signed OAuth request metadata, including the Authorization header, to a cross-origin host. This issue is fixed in version 1.1.6.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;OAuth is a Ruby wrapper for the OAuth 1.0 and 1.0a protocols, providing clients and servers. From 0.5.5 to 1.1.5, OAuth::Consumer#token_request parses the raw Location header of a 300 to 399 redirect returned by the OAuth server and follows the redirect recursively, which can mutate the consumer&amp;#39;s configuration and expose signed OAuth request metadata, including the Authorization header, to a cross-origin host. This issue is fixed in version 1.1.6.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-54605</guid>
    </item>
    <item>
      <title>GHSA-prq8-7wvh-44qh — OAuth: Cross-origin token-request redirects can expose signed request metadata</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-prq8-7wvh-44qh</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: oauth&lt;/p&gt;
&lt;p&gt;# Cross-origin OAuth token-request redirects can expose signed request metadata&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;When an application uses `OAuth::Consumer` to request OAuth 1.0 request tokens or
access tokens, the token request helper follows `300..399` redirects returned by
the OAuth server. In affected versions, `OAuth::Consumer#token_request` parses the
raw `Location` header, follows the redirect recursively, and can mutate the
consumer&amp;#39;s configured `site` when the redirect points to a different host with
the same path.&lt;/p&gt;
&lt;p&gt;The result is a cross-origin signed-request disclosure primitive: if an OAuth
server token endpoint returns a redirect whose target an attacker controls, the
client can re-sign the token request and send OAuth 1.0 request metadata,
including the OAuth signature, nonce, timestamp, consumer key, and any request
parameters included in the signature base string, to the attacker-controlled
host. The same behavior can also be used as an SSRF or confused-deputy primitive
because the application server follows the redirect and sends the next request
from its own network position.&lt;/p&gt;
&lt;p&gt;## Affected&lt;/p&gt;
&lt;p&gt;- `oauth` v1.1.5 and prior versions back to and including v0.5.5.
  - The cross-host token redirect behavior was introduced by
    https://github.com/ruby-oauth/oauth/commit/d74b767f
  - The behavior is documented in the v0.5.5 changelog as &amp;#34;Allow redirect to
    different host but same path&amp;#34;.
- The vulnerable behavior is in `OAuth::Consumer#token_request`, which is used by
  the documented re…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: oauth&lt;/p&gt;
&lt;p&gt;# Cross-origin OAuth token-request redirects can expose signed request metadata&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;When an application uses `OAuth::Consumer` to request OAuth 1.0 request tokens or
access tokens, the token request helper follows `300..399` redirects returned by
the OAuth server. In affected versions, `OAuth::Consumer#token_request` parses the
raw `Location` header, follows the redirect recursively, and can mutate the
consumer&amp;#39;s configured `site` when the redirect points to a different host with
the same path.&lt;/p&gt;
&lt;p&gt;The result is a cross-origin signed-request disclosure primitive: if an OAuth
server token endpoint returns a redirect whose target an attacker controls, the
client can re-sign the token request and send OAuth 1.0 request metadata,
including the OAuth signature, nonce, timestamp, consumer key, and any request
parameters included in the signature base string, to the attacker-controlled
host. The same behavior can also be used as an SSRF or confused-deputy primitive
because the application server follows the redirect and sends the next request
from its own network position.&lt;/p&gt;
&lt;p&gt;## Affected&lt;/p&gt;
&lt;p&gt;- `oauth` v1.1.5 and prior versions back to and including v0.5.5.
  - The cross-host token redirect behavior was introduced by
    https://github.com/ruby-oauth/oauth/commit/d74b767f
  - The behavior is documented in the v0.5.5 changelog as &amp;#34;Allow redirect to
    different host but same path&amp;#34;.
- The vulnerable behavior is in `OAuth::Consumer#token_request`, which is used by
  the documented re…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-prq8-7wvh-44qh</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-54605</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-54605</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: ruby-oauth, Ubuntu:18.04:LTS: ruby-oauth, Ubuntu:20.04:LTS: ruby-oauth, Ubuntu:22.04:LTS: ruby-oauth, Ubuntu:24.04:LTS: ruby-oauth, Ubuntu:26.04:LTS: ruby-oauth&lt;/p&gt;
&lt;p&gt;OAuth is a Ruby wrapper for the OAuth 1.0 and 1.0a protocols, providing clients and servers. From 0.5.5 to 1.1.5, OAuth::Consumer#token_request parses the raw Location header of a 300 to 399 redirect returned by the OAuth server and follows the redirect recursively, which can mutate the consumer&amp;#39;s configuration and expose signed OAuth request metadata, including the Authorization header, to a cross-origin host. This issue is fixed in version 1.1.6.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: ruby-oauth, Ubuntu:18.04:LTS: ruby-oauth, Ubuntu:20.04:LTS: ruby-oauth, Ubuntu:22.04:LTS: ruby-oauth, Ubuntu:24.04:LTS: ruby-oauth, Ubuntu:26.04:LTS: ruby-oauth&lt;/p&gt;
&lt;p&gt;OAuth is a Ruby wrapper for the OAuth 1.0 and 1.0a protocols, providing clients and servers. From 0.5.5 to 1.1.5, OAuth::Consumer#token_request parses the raw Location header of a 300 to 399 redirect returned by the OAuth server and follows the redirect recursively, which can mutate the consumer&amp;#39;s configuration and expose signed OAuth request metadata, including the Authorization header, to a cross-origin host. This issue is fixed in version 1.1.6.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-54605</guid>
    </item>
  </channel>
</rss>
