Security advisory: Possible leak of legacy API keys via improper cache configuration

· Blog Rubygems · July 23, 2026, 1:54 a.m.
Summary
RubyGems.org disclosed a security vulnerability that allowed legacy API keys to be leaked due to a CDN caching issue affecting gem clients older than v3.2.0. The team has revoked all legacy keys and recommends users check their gems for unauthorized changes. They emphasize the importance of transitioning to scoped keys and enabling MFA for better account security.
AUTHOR
BLOG POST FEATURED ON

Add this plugin to your blog