Skip to content

OAuth2::Client#request: Protocol-relative redirect Location overrides authority, leaking bearer Authorization to attacker host

High severity GitHub Reviewed Published Jun 7, 2026 in ruby-oauth/oauth2

No open alerts for this advisory

Give feedback on Dependabot alerts