pay vulnerabilities
CVEs whose affected-version data names the pay package (rubygems). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-70658High· 7.4PoCPay is a payments engine for Ruby on Rails 6.0 and higher
Pay is a payments engine for Ruby on Rails 6.0 and higher. Prior to 11.6.2, Pay::Webhooks::PaddleBillingController#valid_signature? in app/controllers/pay/webhooks/paddle_billing_controller.rb compares the computed 64-character SHA-256 H…
▾ Midnightpay-rails · payEPSS 0.50%via NVD
GHSA-mjgf-xj26-9qf9High· 7.4pay-rails/pay: non-constant-time HMAC comparison in Paddle Billing webhook signature verifier
pay-rails/pay: non-constant-time HMAC comparison in Paddle Billing webhook signature verifier
▾ Twilightpay · payvia GHSA