CVE-2026-70658: CWE-208: Observable Timing Discrepancy in pay-rails pay
Pay is a payments engine for Ruby on Rails 6.0 and higher. Prior to 11.6.2, Pay::Webhooks::PaddleBillingController#valid_signature? in app/controllers/pay/webhooks/paddle_billing_controller.rb compares the computed 64-character SHA-256 HMAC with the attacker-controlled h1 token from the Paddle-Signature header using Ruby String#==. An unauthenticated remote attacker who can repeatedly submit requests to /pay/webhooks/paddle_billing and obtain sufficiently precise timing measurements can infer matching digest prefixes and recover a valid signature. A forged accepted webhook is enqueued through Pay::Webhooks::ProcessJob and can cause a host application to update billing state, provision paid features, record refunds, or trigger customer notifications. This issue is fixed in version 11.6.2.
AI Analysis
Technical Summary
The vulnerability arises from the use of Ruby's String#== method to compare a computed 64-character SHA-256 HMAC with the Paddle-Signature header's attacker-controlled token. Because String#== is not constant-time, an attacker can perform a timing attack by repeatedly submitting requests and measuring response times to recover a valid signature prefix. This allows forging of accepted webhooks that enqueue jobs to update billing state or trigger other sensitive actions in the host application. The flaw affects pay-rails pay versions before 11.6.2 and is resolved in 11.6.2.
Potential Impact
An unauthenticated remote attacker can exploit this timing discrepancy to forge valid webhook signatures, leading to unauthorized billing updates, provisioning of paid features, recording of refunds, or triggering customer notifications. This compromises the integrity of payment processing and billing state management in affected applications.
Mitigation Recommendations
Upgrade to pay-rails pay version 11.6.2 or later, where the timing discrepancy vulnerability in PaddleBillingController#valid_signature? is fixed. No other mitigations are indicated by the vendor advisory.
CVE-2026-70658: CWE-208: Observable Timing Discrepancy in pay-rails pay
Description
Pay is a payments engine for Ruby on Rails 6.0 and higher. Prior to 11.6.2, Pay::Webhooks::PaddleBillingController#valid_signature? in app/controllers/pay/webhooks/paddle_billing_controller.rb compares the computed 64-character SHA-256 HMAC with the attacker-controlled h1 token from the Paddle-Signature header using Ruby String#==. An unauthenticated remote attacker who can repeatedly submit requests to /pay/webhooks/paddle_billing and obtain sufficiently precise timing measurements can infer matching digest prefixes and recover a valid signature. A forged accepted webhook is enqueued through Pay::Webhooks::ProcessJob and can cause a host application to update billing state, provision paid features, record refunds, or trigger customer notifications. This issue is fixed in version 11.6.2.
CVSS v3.1
Score 7.4high
Affected software
pay-rails
pay
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability arises from the use of Ruby's String#== method to compare a computed 64-character SHA-256 HMAC with the Paddle-Signature header's attacker-controlled token. Because String#== is not constant-time, an attacker can perform a timing attack by repeatedly submitting requests and measuring response times to recover a valid signature prefix. This allows forging of accepted webhooks that enqueue jobs to update billing state or trigger other sensitive actions in the host application. The flaw affects pay-rails pay versions before 11.6.2 and is resolved in 11.6.2.
Potential Impact
An unauthenticated remote attacker can exploit this timing discrepancy to forge valid webhook signatures, leading to unauthorized billing updates, provisioning of paid features, recording of refunds, or triggering customer notifications. This compromises the integrity of payment processing and billing state management in affected applications.
Mitigation Recommendations
Upgrade to pay-rails pay version 11.6.2 or later, where the timing discrepancy vulnerability in PaddleBillingController#valid_signature? is fixed. No other mitigations are indicated by the vendor advisory.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-08-04T21:48:08.613Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6aa8300255bf5e2cf5600a70
Added to database: 09/14/2026, 17:33:54 UTC
Last enriched: 09/14/2026, 17:46:27 UTC
Last updated: 09/15/2026, 04:24:49 UTC
Views: 12
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.