Security advisory: Possible leak of legacy API keys via improper cache configuration

211 · Blog Rubygems · July 23, 2026, 1:54 a.m.
Summary
RubyGems.org disclosed a security vulnerability that allowed legacy API keys to be leaked due to a CDN caching issue affecting gem clients older than v3.2.0. The team has revoked all legacy keys and recommends users check their gems for unauthorized changes. They emphasize the importance of transitioning to scoped keys and enabling MFA for better account security.