Debian Package Tracker
Register | Log in
Subscribe

ruby-oauth2

ruby wrapper for the OAuth 2.0 protocol

Choose email to subscribe with

general
  • source: ruby-oauth2 (main)
  • version: 2.0.18-1
  • maintainer: Debian Ruby Team (archive) (DMD)
  • uploaders: Pirate Praveen [DMD]
  • arch: all
  • std-ver: 4.7.3
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 1.4.4-1
  • oldstable: 1.4.4-1
  • stable: 2.0.9-1
  • testing: 2.0.18-1
  • unstable: 2.0.25-1
versioned links
  • 1.4.4-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.0.9-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.0.18-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.0.25-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • ruby-oauth2
action needed
Marked for autoremoval on 12 September: #1143054 high
Version 2.0.18-1 of ruby-oauth2 is marked for autoremoval from testing on Sat 12 Sep 2026. It is affected by #1143054. The removal of ruby-oauth2 will also cause the removal of (transitive) reverse dependencies: debci, ruby-asana, ruby-omniauth-alicloud, ruby-omniauth-atlassian-oauth2, ruby-omniauth-authentiq, ruby-omniauth-azure-activedirectory-v2, ruby-omniauth-dingtalk-oauth2, ruby-omniauth-facebook, ruby-omniauth-github, ruby-omniauth-gitlab, ruby-omniauth-google-oauth2, ruby-omniauth-oauth2, ruby-omniauth-oauth2-generic, ruby-omniauth-wordpress, ruby-vagrant-cloud. You should try to prevent the removal by fixing these RC bugs.
Created: 2026-08-06 Last update: 2026-08-10 06:30
1 security issue in trixie high

There is 1 open security issue in trixie.

1 important issue:
  • CVE-2026-54603: OAuth2 is a Ruby wrapper for the OAuth 2.0 and 2.1 authorization frameworks, including OpenID Connect (OIDC). From 0.4.0 to 2.0.21, a protocol-relative redirect Location returned to OAuth2::Client#request overrides the request authority, so the bearer Authorization header is sent to an attacker-controlled host, leaking the credential. This issue is fixed in version 2.0.22.
Created: 2026-07-29 Last update: 2026-08-10 05:33
1 security issue in sid high

There is 1 open security issue in sid.

1 important issue:
  • CVE-2026-54603: OAuth2 is a Ruby wrapper for the OAuth 2.0 and 2.1 authorization frameworks, including OpenID Connect (OIDC). From 0.4.0 to 2.0.21, a protocol-relative redirect Location returned to OAuth2::Client#request overrides the request authority, so the bearer Authorization header is sent to an attacker-controlled host, leaking the credential. This issue is fixed in version 2.0.22.
Created: 2026-07-29 Last update: 2026-08-10 05:33
1 security issue in forky high

There is 1 open security issue in forky.

1 important issue:
  • CVE-2026-54603: OAuth2 is a Ruby wrapper for the OAuth 2.0 and 2.1 authorization frameworks, including OpenID Connect (OIDC). From 0.4.0 to 2.0.21, a protocol-relative redirect Location returned to OAuth2::Client#request overrides the request authority, so the bearer Authorization header is sent to an attacker-controlled host, leaking the credential. This issue is fixed in version 2.0.22.
Created: 2026-07-29 Last update: 2026-08-10 05:33
1 security issue in bullseye high

There is 1 open security issue in bullseye.

1 important issue:
  • CVE-2026-54603: OAuth2 is a Ruby wrapper for the OAuth 2.0 and 2.1 authorization frameworks, including OpenID Connect (OIDC). From 0.4.0 to 2.0.21, a protocol-relative redirect Location returned to OAuth2::Client#request overrides the request authority, so the bearer Authorization header is sent to an attacker-controlled host, leaking the credential. This issue is fixed in version 2.0.22.
Created: 2026-07-29 Last update: 2026-08-10 05:33
1 security issue in bookworm high

There is 1 open security issue in bookworm.

1 important issue:
  • CVE-2026-54603: OAuth2 is a Ruby wrapper for the OAuth 2.0 and 2.1 authorization frameworks, including OpenID Connect (OIDC). From 0.4.0 to 2.0.21, a protocol-relative redirect Location returned to OAuth2::Client#request overrides the request authority, so the bearer Authorization header is sent to an attacker-controlled host, leaking the credential. This issue is fixed in version 2.0.22.
Created: 2026-07-29 Last update: 2026-08-10 05:33
The VCS repository is not up to date, push the missing commits. high
vcswatch reports that this package has been uploaded into the archive but the debian/changelog in the VCS is still UNRELEASED. You should consider pushing the missing commits or updating the VCS.

https://salsa.debian.org/api/v4/projects/ruby-team%2Fruby-oauth2 API request failed: 401 Unauthorized at /srv/qa.debian.org/data/vcswatch/vcswatch line 410.
Created: 2026-08-10 Last update: 2026-08-10 03:31
testing migrations
  • excuses:
    • Migrates after: ruby-anonymous-loader
    • Migration status for ruby-oauth2 (2.0.18-1 to 2.0.25-1): Waiting for test results or another package, or too young (no action required now - check later)
    • Issues preventing migration:
    • ∙ ∙ Autopkgtest for ruby-asana/2.0.3-1: amd64: Test triggered, arm64: Test triggered, armhf: No tests, superficial or marked flaky ♻ (reference ♻), i386: Test triggered, loong64: Test triggered, ppc64el: Test triggered, riscv64: Test triggered, s390x: Test triggered
    • ∙ ∙ Autopkgtest for ruby-oauth2/2.0.25-1: amd64: Test triggered, arm64: Test triggered, armhf: No tests, superficial or marked flaky ♻ (reference ♻), i386: Test triggered, loong64: Test triggered, ppc64el: Test triggered, riscv64: Test triggered, s390x: Test triggered
    • ∙ ∙ Autopkgtest for ruby-omniauth-google-oauth2/1.2.2-1: amd64: Test triggered, arm64: Test triggered, armhf: Pass, i386: Test triggered, loong64: Test triggered, ppc64el: Test triggered, riscv64: Test triggered, s390x: Test triggered
    • ∙ ∙ Autopkgtest for ruby-omniauth-oauth2/1.9.0-1: amd64: Test triggered, arm64: Test triggered, armhf: Pass, i386: Test triggered, loong64: Test triggered, ppc64el: Test triggered, riscv64: Test triggered, s390x: Test triggered
    • ∙ ∙ Autopkgtest for ruby-vagrant-cloud/3.1.3-1: amd64: Test triggered, arm64: Test triggered, armhf: Pass, i386: Test triggered, loong64: Test triggered, ppc64el: Test triggered, riscv64: Test triggered, s390x: Test triggered
    • ∙ ∙ Lintian check waiting for test results - info
    • ∙ ∙ Too young, only 0 of 5 days old
    • ∙ ∙ Depends: ruby-oauth2 ruby-anonymous-loader
    • Additional info (not blocking):
    • ∙ ∙ Updating ruby-oauth2 will fix bugs in testing: #1143054
    • ∙ ∙ Piuparts tested OK - https://piuparts.debian.org/sid/source/r/ruby-oauth2.html
    • ∙ ∙ Reproduced on amd64 - info
    • ∙ ∙ Reproduced on arm64 - info
    • ∙ ∙ Reproduced on armhf - info
    • ∙ ∙ Reproduced on i386 - info
    • Not considered
news
[rss feed]
  • [2026-08-10] Accepted ruby-oauth2 2.0.25-1 (source) into unstable (Simon Quigley)
  • [2026-02-14] ruby-oauth2 2.0.18-1 MIGRATED to testing (Debian testing watch)
  • [2026-02-08] Accepted ruby-oauth2 2.0.18-1 (source) into unstable (Simon Quigley)
  • [2025-11-02] ruby-oauth2 2.0.17-1 MIGRATED to testing (Debian testing watch)
  • [2025-10-24] Accepted ruby-oauth2 2.0.17-1 (source) into unstable (Simon Quigley)
  • [2025-02-04] ruby-oauth2 2.0.9-1 MIGRATED to testing (Debian testing watch)
  • [2025-01-29] Accepted ruby-oauth2 2.0.9-1 (source) into unstable (Antonio Terceiro)
  • [2023-06-13] ruby-oauth2 2.0.7-2 MIGRATED to testing (Debian testing watch)
  • [2023-02-10] Accepted ruby-oauth2 2.0.7-2 (source) into unstable (Mohammed Bilal)
  • [2022-12-04] Accepted ruby-oauth2 2.0.7-1 (source) into experimental (Ajayi Olatunji O.) (signed by: Mohammed Bilal)
  • [2020-07-03] Accepted ruby-oauth2 1.4.4-1~bpo10+1 (source all) into buster-backports, buster-backports (Debian FTP Masters) (signed by: Praveen Arimbrathodiyil)
  • [2020-07-01] ruby-oauth2 1.4.4-1 MIGRATED to testing (Debian testing watch)
  • [2020-06-23] Accepted ruby-oauth2 1.4.4-1 (source) into unstable (Pirate Praveen) (signed by: Praveen Arimbrathodiyil)
  • [2019-07-09] ruby-oauth2 1.4.1-2 MIGRATED to testing (Debian testing watch)
  • [2019-04-15] Accepted ruby-oauth2 1.4.1-2 (source) into unstable (Gianfranco Costamagna)
  • [2019-02-08] ruby-oauth2 1.4.1-1 MIGRATED to testing (Debian testing watch)
  • [2019-02-05] Accepted ruby-oauth2 1.4.1-1 (source) into unstable (Pirate Praveen) (signed by: Praveen Arimbrathodiyil)
  • [2018-05-18] Accepted ruby-oauth2 1.4.0-3~bpo9+1 (source all) into stretch-backports, stretch-backports (Pirate Praveen) (signed by: Praveen Arimbrathodiyil)
  • [2018-05-02] ruby-oauth2 1.4.0-3 MIGRATED to testing (Debian testing watch)
  • [2018-04-26] Accepted ruby-oauth2 1.4.0-3 (source) into unstable (Balint Reczey)
  • [2017-09-17] ruby-oauth2 1.4.0-2 MIGRATED to testing (Debian testing watch)
  • [2017-09-11] Accepted ruby-oauth2 1.4.0-2 (source) into unstable (Pirate Praveen) (signed by: Praveen Arimbrathodiyil)
  • [2017-08-01] ruby-oauth2 1.4.0-1 MIGRATED to testing (Debian testing watch)
  • [2017-07-27] Accepted ruby-oauth2 1.4.0-1 (source) into unstable (Pirate Praveen) (signed by: Praveen Arimbrathodiyil)
  • [2016-07-20] ruby-oauth2 1.2.0-1 MIGRATED to testing (Debian testing watch)
  • [2016-07-14] Accepted ruby-oauth2 1.2.0-1 (source) into unstable (Pirate Praveen) (signed by: Praveen Arimbrathodiyil)
  • [2015-07-11] ruby-oauth2 1.0.0-2 MIGRATED to testing (Britney)
  • [2015-07-10] ruby-oauth2 REMOVED from testing (Britney)
  • [2015-05-19] ruby-oauth2 1.0.0-2 MIGRATED to testing (Britney)
  • [2015-05-13] Accepted ruby-oauth2 1.0.0-2 (source all) into unstable (Pirate Praveen) (signed by: Praveen Arimbrathodiyil)
  • 1
  • 2
bugs [bug history graph]
  • all: 1
  • RC: 0
  • I&N: 1
  • M&W: 0
  • F&P: 0
  • patch: 0
links
  • homepage
  • buildd: logs, reproducibility
  • popcon
  • browse source code
  • other distros
  • security tracker
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 2.0.18-1

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing