Your message dated Mon, 10 Aug 2026 00:49:03 +0000
with message-id <[email protected]>
and subject line Bug#1143054: fixed in ruby-oauth2 2.0.25-1
has caused the Debian Bug report #1143054,
regarding ruby-oauth2: CVE-2026-54603
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
1143054: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1143054
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: ruby-oauth2
Version: 2.0.18-1
Severity: grave
Tags: security upstream
Justification: user security hole
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerability was published for ruby-oauth2.

CVE-2026-54603[0]:
| OAuth2 is a Ruby wrapper for the OAuth 2.0 and 2.1 authorization
| frameworks, including OpenID Connect (OIDC). From 0.4.0 to 2.0.21, a
| protocol-relative redirect Location returned to
| OAuth2::Client#request overrides the request authority, so the
| bearer Authorization header is sent to an attacker-controlled host,
| leaking the credential. This issue is fixed in version 2.0.22.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-54603
    https://www.cve.org/CVERecord?id=CVE-2026-54603
[1] https://github.com/ruby-oauth/oauth2/security/advisories/GHSA-pp92-crg2-gfv9
[2] 
https://github.com/ruby-oauth/oauth2/commit/0f0a474f1b38453e119e660c2daca742d4378ce9

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

--- End Message ---
--- Begin Message ---
Source: ruby-oauth2
Source-Version: 2.0.25-1
Done: Simon Quigley <[email protected]>

We believe that the bug you reported is fixed in the latest version of
ruby-oauth2, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Simon Quigley <[email protected]> (supplier of updated ruby-oauth2 package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Sun, 09 Aug 2026 19:34:22 -0500
Source: ruby-oauth2
Architecture: source
Version: 2.0.25-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Ruby Team 
<[email protected]>
Changed-By: Simon Quigley <[email protected]>
Closes: 1143054
Changes:
 ruby-oauth2 (2.0.25-1) unstable; urgency=medium
 .
   * Team upload.
   * Use GitHub tags in the watch file.
   * New upstream release (Closes: #1143054).
   * Refresh the upstream metadata.
   * Update Standards-Version to 4.7.4.
   * Bump debhelper-compat to 14, dropping ${misc:Depends},
     ${shlibs:Depends}, and ${ruby:Depends} from runtime dependencies.
   * Update build dependencies.
   * Update the Homepage URL.
Checksums-Sha1:
 52dbb10add120fa7fae35ebebf8ca0f2036106f3 2235 ruby-oauth2_2.0.25-1.dsc
 b9ed964dd19b770db9b97d23b2c05cd71cfb37b5 366433 ruby-oauth2_2.0.25.orig.tar.gz
 fadfcb0c501928b24050c5f9e454799db3d4eda0 3652 
ruby-oauth2_2.0.25-1.debian.tar.xz
 54824612483bfc1bcc478651a3bee61bb3a8725c 7588 
ruby-oauth2_2.0.25-1_source.buildinfo
Checksums-Sha256:
 bc157dd5835d1226519fff1c0953d5dac8c48ff6913d514ed795f605d1feaf2c 2235 
ruby-oauth2_2.0.25-1.dsc
 5be4b2bb8df409634630c9169030388e480f4eb58226beca0396717d95b93daf 366433 
ruby-oauth2_2.0.25.orig.tar.gz
 a0718de8a5a251d3d6554ca8f1bf4cb4e89e9b6accbe44edff6f0faa5c764b09 3652 
ruby-oauth2_2.0.25-1.debian.tar.xz
 19dc41899fa959822a2dae26a8b1189b2a45316bb854a982af01c78f57edecb4 7588 
ruby-oauth2_2.0.25-1_source.buildinfo
Files:
 caf283e5c7e64a24fd9a876283ffd723 2235 ruby optional ruby-oauth2_2.0.25-1.dsc
 bd55249ee65526ad9624b2c77695bd5e 366433 ruby optional 
ruby-oauth2_2.0.25.orig.tar.gz
 2ff3c3d6a015d5c06abcc97fc041cc56 3652 ruby optional 
ruby-oauth2_2.0.25-1.debian.tar.xz
 10b8c89a61015a8466412a32ae491303 7588 ruby optional 
ruby-oauth2_2.0.25-1_source.buildinfo

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEXHq+og+GMEWcyMi14n8s+EWML6QFAmp5HK8ACgkQ4n8s+EWM
L6RdexAAuo70CsOWEMblzqfZ+rrwERqv8R9nAJFLR4ZdtFkYNKLu8rtOr9vF0BoT
sy5rranV36b68k7lqEBOhG7JN6OsI664YLCovpY+rfCMj1Nu4A0UpQzNu1PDFaeZ
9Jr7EZN6ypvepVqCRJcxIXqzddnaMvDXJtu7pMRAIby7xkjEcviTuLueRwMUMjjM
t/EWv7YiLnlXBXbYlc0tRF3gmxDFnZnNeW4NrgKt1iKaVeEdO0QLU5LbQ357dON9
OKtrEOyK9Cq6IdFY3VbaFjBRNKPDN2qHj3J4QLImxicNkSgFLerFiAk4D8hgkA1J
6Cxvw6ASW2lechW0p7IqsE3bk2E6y1qIgU92Q/76Z7OZDS1LMRkUfBlZgWSz+g4m
jR5ROtFIEp/z11fxqooaQqA7wm5T0SQkN+F+v15UDwB52LhiSoNTEQpcNcHXLtHM
UIVXUmSYuRDAUHk3jsqlNwzlm6BFtSOsQc2wlnZRghF0XUytj0P/BTf7o6EzT/EV
7wwErbIe5/oFqN1qvabPaCxHUZgGxrNj5iY97CB2dyo68HJJ1Wtfc8PIwckKgNiE
PzVXlTbWhQpXct4gzO9rRpC8r4dnvQG6qwxNXrE9xKp0PqERph3MN3R6VvmmsZ83
RhPpJ3qKOYpRySpQZwES5yoOcYdHfTmg/UQL60ku9W3RXXF7QAY=
=8GjI
-----END PGP SIGNATURE-----

Attachment: pgpDPHgk5vSVR.pgp
Description: PGP signature


--- End Message ---

Reply via email to