๐Ÿ” CVE Alert

CVE-2026-105221

HIGH 7.4

Gist RubyGem before 6.1.0 Disabled TLS Certificate Verification

CVSS Score
7.4
EPSS Score
0.0%
EPSS Percentile
0th

The gist RubyGem before 6.1.0 contains an improper certificate validation vulnerability that allows on-path attackers to intercept HTTPS traffic because http_connection in lib/gist.rb sets VERIFY_NONE. Attackers can present any certificate to read or modify GitHub API traffic, stealing OAuth tokens and login credentials to read and modify the victim's gists.

CWE CWE-295
Vendor defunkt
Product gist
Published Oct 4, 2026
Stay Ahead of the Next One

Get instant alerts for defunkt gist

Be the first to know when new high vulnerabilities affecting defunkt gist are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None

Affected Versions

defunkt / gist
4.0.0 < 6.1.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/defunkt/gist/issues/373 github.com: https://github.com/defunkt/gist github.com: https://github.com/defunkt/gist/blob/v6.0.0/lib/gist.rb#L466-L468 github.com: https://github.com/defunkt/gist/commit/07ccc1a6d46e9d36f0e85d0b1c5d795890ae6bcf vulncheck.com: https://www.vulncheck.com/advisories/gist-rubygem-before-6.1.0-disabled-tls-certificate-verification

Credits

Siyang Wu