CVE-2026-66901 | CJCOLLIER Google::Auth up to 0.8 URL Validation fetch_subject_token credential_source.url/token_url server-side request forgery

SecurityVulns

A vulnerability was found in CJCOLLIER Google::Auth up to 0.8. It has been declared as problematic. This issue affects the function fetch_subject_token of the component URL Validation. Executing a manipulation of the argument credential_source.url/token_url can lead to server-side request forgery.

This vulnerability is tracked as CVE-2026-66901. The attack can be launched remotely. No exploit exists.

It is recommended to upgrade the affected component.VulDB Recent EntriesRead More