CVE-2026-40295
Devise is an authentication solution for Rails based on Warden. In versions 5.0.3 and below, when the Timeoutable module is enabled in Devise, the FailureApp#redirect_url method returns request.referrer — the HTTP Referer header, which is attacker-controllable — without validation for any non-GET request that results in a session timeout. An attacker who hosts a page with an auto-submitting cross-origin form can cause a victim with an expired Devise session to be redirected to an arbitrary external URL.
Leer descripción completaMostrar menos
This contrasts with the GET timeout path (which uses server-side attempted_path) and Devise's own store_location_for mechanism (which strips external hosts via extract_path_from_location), both of which are protected; only the non-GET timeout redirect path is unprotected. Expired-session users can be silently redirected from the trusted app domain to attacker-controlled URLs, enabling phishing and malware delivery while bypassing browser warnings. Note: Rails' built-in open-redirect protection does not mitigate this issue. Devise::FailureApp is an ActionController::Metal app with its own isolated copy of the relevant redirect configuration, so config.action_controller.action_on_open_redirect = :raise (and the older raise_on_open_redirects setting) do not reach it. This issue has been fixed in version 5.0.4.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- Puntuación base: 6.1
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.32%
- Percentil entre todas las CVEs puntuadas: 23
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-601
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-40295",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-40295",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-05-26T13:09:47.384783Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 6.1,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "LOW"
},
"impactScore": 2.7,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "security-advisories@github.com",
"affectedData": [
{
"vendor": "heartcombo",
"product": "devise",
"versions": [
{
"status": "affected",
"version": "< 5.0.4"
}
]
}
]
}
],
"published": "2026-05-22T20:16:34.013",
"references": [
{
"url": "https://github.com/heartcombo/devise/commit/025fe2124f9928766fc46520e999633b598d0360",
"tags": [
"Patch"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/heartcombo/devise/security/advisories/GHSA-jp94-3292-c3xv",
"tags": [
"Mitigation",
"Vendor Advisory"
],
"source": "security-advisories@github.com"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"description": [
{
"lang": "en",
"value": "CWE-601"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Devise is an authentication solution for Rails based on Warden. In versions 5.0.3 and below, when the Timeoutable module is enabled in Devise, the FailureApp#redirect_url method returns request.referrer — the HTTP Referer header, which is attacker-controllable — without validation for any non-GET request that results in a session timeout. An attacker who hosts a page with an auto-submitting cross-origin form can cause a victim with an expired Devise session to be redirected to an arbitrary external URL. This contrasts with the GET timeout path (which uses server-side attempted_path) and Devise's own store_location_for mechanism (which strips external hosts via extract_path_from_location), both of which are protected; only the non-GET timeout redirect path is unprotected. Expired-session users can be silently redirected from the trusted app domain to attacker-controlled URLs, enabling phishing and malware delivery while bypassing browser warnings. Note: Rails' built-in open-redirect protection does not mitigate this issue. Devise::FailureApp is an ActionController::Metal app with its own isolated copy of the relevant redirect configuration, so config.action_controller.action_on_open_redirect = :raise (and the older raise_on_open_redirects setting) do not reach it. This issue has been fixed in version 5.0.4."
},
{
"lang": "es",
"value": "Devise es una solución de autenticación para Rails basada en Warden. En las versiones 5.0.3 e inferiores, cuando el módulo Timeoutable está habilitado en Devise, el método FailureApp#redirect_url devuelve request.referrer - el encabezado HTTP Referer, que es controlable por el atacante - sin validación para cualquier solicitud que no sea GET que resulte en un tiempo de espera de sesión. Un atacante que aloja una página con un formulario de origen cruzado de envío automático puede hacer que una víctima con una sesión de Devise caducada sea redirigida a una URL externa arbitraria. Esto contrasta con la ruta de tiempo de espera GET (que utiliza attempted_path del lado del servidor) y el propio mecanismo store_location_for de Devise (que elimina hosts externos a través de extract_path_from_location), ambos protegidos; solo la ruta de redirección de tiempo de espera que no es GET está desprotegida. Los usuarios con sesión caducada pueden ser redirigidos silenciosamente desde el dominio de la aplicación de confianza a URL controladas por el atacante, lo que permite el phishing y la entrega de malware mientras se evitan las advertencias del navegador. Nota: La protección de redirección abierta incorporada de Rails no mitiga este problema. Devise::FailureApp es una aplicación ActionController::Metal con su propia copia aislada de la configuración de redirección relevante, por lo que config.action_controller.action_on_open_redirect = :raise (y la configuración más antigua raise_on_open_redirects) no la alcanzan. Este problema ha sido solucionado en la versión 5.0.4."
}
],
"lastModified": "2026-07-23T16:10:00.137",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:heartcombo:devise:*:*:*:*:*:ruby:*:*",
"vulnerable": true,
"matchCriteriaId": "105ECF82-E1F4-4316-A43F-E6AD3A377191",
"versionEndExcluding": "5.0.4"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security-advisories@github.com"
}