{"id":"CVE-2026-105221","summary":"Gist RubyGem before 6.1.0 Disabled TLS Certificate Verification","details":"The gist RubyGem before 6.1.0 contains an improper certificate validation vulnerability that allows on-path attackers to intercept HTTPS traffic because http_connection in lib/gist.rb sets VERIFY_NONE. Attackers can present any certificate to read or modify GitHub API traffic, stealing OAuth tokens and login credentials to read and modify the victim's gists.","modified":"2026-10-06T02:47:15.348183089Z","published":"2026-10-04T22:31:47.153Z","database_specific":{"cna_assigner":"VulnCheck","cwe_ids":["CWE-295"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/105xxx/CVE-2026-105221.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/105xxx/CVE-2026-105221.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105221"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/gist-rubygem-before-6.1.0-disabled-tls-certificate-verification"},{"type":"REPORT","url":"https://github.com/defunkt/gist/issues/373"},{"type":"FIX","url":"https://github.com/defunkt/gist/commit/07ccc1a6d46e9d36f0e85d0b1c5d795890ae6bcf"},{"type":"PACKAGE","url":"https://github.com/defunkt/gist"},{"type":"ARTICLE","url":"https://github.com/defunkt/gist/blob/v6.0.0/lib/gist.rb#L466-L468"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/defunkt/gist","events":[{"introduced":"d6de1c47b2549b00e1d26c08eaefce962c9390b1"},{"fixed":"9c684d1f683460b9501e3efcb95edcb32487ddfe"}],"database_specific":{"extracted_events":[{"introduced":"4.0.0"},{"fixed":"6.1.0"}],"source":"AFFECTED_FIELD"}}],"versions":["v6.0.0","v5.1.0","v5.0.0","v4.6.2","v4.6.1","v4.6.0","v4.5.0","v4.4.2","v4.4.1","v4.4.0","v4.3.0","v4.2.1","v4.1.3","v4.1.2","v4.1.1","v4.1.0","v4.0.3","v4.0.2","v4.0.1","v4.0.0"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-105221.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"}]}