Pay is a payments engine for Ruby on Rails 6.0 and higher. Prior to 11.6.2, Pay::Webhooks::PaddleBillingController#valid_signature? in app/controllers/pay/webhooks/paddle_billing_controller.rb compares the computed 64-character SHA-256 HMAC with the attacker-controlled h1 token from the Paddle-Signature header using Ruby String#==. An unauthenticated remote attacker who can repeatedly submit requests to /pay/webhooks/paddle_billing and obtain sufficiently precise timing measurements can infer matching digest prefixes and recover a valid signature. A forged accepted webhook is enqueued through Pay::Webhooks::ProcessJob and can cause a host application to update billing state, provision paid features, record refunds, or trigger customer notifications. This issue is fixed in version 11.6.2.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-14 18:19
Updated : 2026-09-14 19:17
NVD link : CVE-2026-70658
Mitre link : CVE-2026-70658
CVE.ORG link : CVE-2026-70658
JSON object : View
Products Affected
No product.
CWE
CWE-208
Observable Timing Discrepancy
