Security advisory: Possible leak of legacy API keys via improper cache configuration
23-Jul-2026 9
Originally appeared on RubyGems Blog.A CDN caching bug on RubyGems.org could hand one account’s API key to another person for up to an hour. If you signed in to RubyGems.org with a gem client older than v3.2.0, your key could have been exposed (the technical details are below)...