CVE-2026-70658 | pay-rails pay up to 11.6.1 Webhook paddle_billing_controller.rb PaddleBillingController#valid_signature h1 random values
A vulnerability, which was classified as problematic, was found in pay-rails pay up to 11.6.1. Affected is the function Pay::Webhooks::PaddleBillingController#valid_signature of the file app/controllers/pay/webhooks/paddle_billing_controller.rb of the component Webhook. Such manipulation of the argument h1 leads to insufficiently random values.
This vulnerability is uniquely identified as CVE-2026-70658. The attack can be launched remotely. No exploit exists.
You should upgrade the affected component.VulDB Recent EntriesRead More