Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-105221— Gist RubyGem before 6.1.0 Disabled TLS Certificate Verification

Quick assessment

Affected
defunkt gist
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

6.1.0 版本之前的 gist RubyGem 存在证书验证不当的安全漏洞,允许网络路径上的攻击者拦截 HTTPS 流量。由于 lib/gist.rb 中的 http_connection 设置了 VERIFY_NONE(不验证证书),攻击者可以提供任意证书以读取或篡改 GitHub API 流量,从而窃取 OAuth 令牌和登录凭据,进而读取和修改受害者的 gist 内容。

CVSS 7.4 · High

Possible ATT&CK Techniques 1 AI

T1557 · Adversary-in-the-Middle
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-105221

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Gist RubyGem before 6.1.0 Disabled TLS Certificate Verification
Source: CVE Program / CVE List V5
Vulnerability Description
The gist RubyGem before 6.1.0 contains an improper certificate validation vulnerability that allows on-path attackers to intercept HTTPS traffic because http_connection in lib/gist.rb sets VERIFY_NONE. Attackers can present any certificate to read or modify GitHub API traffic, stealing OAuth tokens and login credentials to read and modify the victim's gists.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
证书验证不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
defunkt gist 4.0.0 ~ 6.1.0 -

II. Public POCs for CVE-2026-105221

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-105221

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-105221 (1)

Vendor Advisories for CVE-2026-105221 (1)

Security Blog Posts for CVE-2026-105221 (1)

Other References for CVE-2026-105221 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-105221

No comments yet


Leave a comment