pay
Payments for Ruby on Rails apps
Activity
- Latest release
- 3w ago
- Total releases
- 159
- Cadence
- ~7 days
- Last 12 months
- 13
Reach
- Downloads
- 2.0M
- Stars
- 2.3k
Details
- License
- MIT
- First release
- Feb 01, 2017
| Version | Released | |
|---|---|---|
11.7.2
patch
| ||
11.7.1
patch
| ||
11.7.0
minor
| ||
11.6.2
patch
| ||
11.6.1
patch
1 CVE
GHSA-mjgf-xj26-9qf9
Jul 01, 2026
pay-rails/pay: non-constant-time HMAC comparison in Paddle Billing webhook signature verifier
7.4
/ 10
High
Network
High
None
None
Unchanged
High
High
None
Summary
Impact
Affected versions
Vulnerable code (file:line)
How an attacker reaches this code
Proof of concept (microbenchmark)Local Ruby microbenchmark isolating the verifier comparison path:
This isolates the same End-to-end reproduction against
| ||
11.6.0
minor
1 CVE
GHSA-mjgf-xj26-9qf9
Jul 01, 2026
pay-rails/pay: non-constant-time HMAC comparison in Paddle Billing webhook signature verifier
7.4
/ 10
High
Network
High
None
None
Unchanged
High
High
None
Summary
Impact
Affected versions
Vulnerable code (file:line)
How an attacker reaches this code
Proof of concept (microbenchmark)Local Ruby microbenchmark isolating the verifier comparison path:
This isolates the same End-to-end reproduction against
| ||
11.5.0
minor
1 CVE
GHSA-mjgf-xj26-9qf9
Jul 01, 2026
pay-rails/pay: non-constant-time HMAC comparison in Paddle Billing webhook signature verifier
7.4
/ 10
High
Network
High
None
None
Unchanged
High
High
None
Summary
Impact
Affected versions
Vulnerable code (file:line)
How an attacker reaches this code
Proof of concept (microbenchmark)Local Ruby microbenchmark isolating the verifier comparison path:
This isolates the same End-to-end reproduction against
| ||
11.4.3
patch
1 CVE
GHSA-mjgf-xj26-9qf9
Jul 01, 2026
pay-rails/pay: non-constant-time HMAC comparison in Paddle Billing webhook signature verifier
7.4
/ 10
High
Network
High
None
None
Unchanged
High
High
None
Summary
Impact
Affected versions
Vulnerable code (file:line)
How an attacker reaches this code
Proof of concept (microbenchmark)Local Ruby microbenchmark isolating the verifier comparison path:
This isolates the same End-to-end reproduction against
| ||
11.4.2
patch
1 CVE
GHSA-mjgf-xj26-9qf9
Jul 01, 2026
pay-rails/pay: non-constant-time HMAC comparison in Paddle Billing webhook signature verifier
7.4
/ 10
High
Network
High
None
None
Unchanged
High
High
None
Summary
Impact
Affected versions
Vulnerable code (file:line)
How an attacker reaches this code
Proof of concept (microbenchmark)Local Ruby microbenchmark isolating the verifier comparison path:
This isolates the same End-to-end reproduction against
| ||
11.4.1
patch
1 CVE
GHSA-mjgf-xj26-9qf9
Jul 01, 2026
pay-rails/pay: non-constant-time HMAC comparison in Paddle Billing webhook signature verifier
7.4
/ 10
High
Network
High
None
None
Unchanged
High
High
None
Summary
Impact
Affected versions
Vulnerable code (file:line)
How an attacker reaches this code
Proof of concept (microbenchmark)Local Ruby microbenchmark isolating the verifier comparison path:
This isolates the same End-to-end reproduction against
| ||
11.4.0
minor
1 CVE
GHSA-mjgf-xj26-9qf9
Jul 01, 2026
pay-rails/pay: non-constant-time HMAC comparison in Paddle Billing webhook signature verifier
7.4
/ 10
High
Network
High
None
None
Unchanged
High
High
None
Summary
Impact
Affected versions
Vulnerable code (file:line)
How an attacker reaches this code
Proof of concept (microbenchmark)Local Ruby microbenchmark isolating the verifier comparison path:
This isolates the same End-to-end reproduction against
| ||
11.3.1
patch
1 CVE
GHSA-mjgf-xj26-9qf9
Jul 01, 2026
pay-rails/pay: non-constant-time HMAC comparison in Paddle Billing webhook signature verifier
7.4
/ 10
High
Network
High
None
None
Unchanged
High
High
None
Summary
Impact
Affected versions
Vulnerable code (file:line)
How an attacker reaches this code
Proof of concept (microbenchmark)Local Ruby microbenchmark isolating the verifier comparison path:
This isolates the same End-to-end reproduction against
| ||
11.3.0
minor
1 CVE
GHSA-mjgf-xj26-9qf9
Jul 01, 2026
pay-rails/pay: non-constant-time HMAC comparison in Paddle Billing webhook signature verifier
7.4
/ 10
High
Network
High
None
None
Unchanged
High
High
None
Summary
Impact
Affected versions
Vulnerable code (file:line)
How an attacker reaches this code
Proof of concept (microbenchmark)Local Ruby microbenchmark isolating the verifier comparison path:
This isolates the same End-to-end reproduction against
| ||
11.2.3
patch
1 CVE
GHSA-mjgf-xj26-9qf9
Jul 01, 2026
pay-rails/pay: non-constant-time HMAC comparison in Paddle Billing webhook signature verifier
7.4
/ 10
High
Network
High
None
None
Unchanged
High
High
None
Summary
Impact
Affected versions
Vulnerable code (file:line)
How an attacker reaches this code
Proof of concept (microbenchmark)Local Ruby microbenchmark isolating the verifier comparison path:
This isolates the same End-to-end reproduction against
| ||
11.2.2
patch
1 CVE
GHSA-mjgf-xj26-9qf9
Jul 01, 2026
pay-rails/pay: non-constant-time HMAC comparison in Paddle Billing webhook signature verifier
7.4
/ 10
High
Network
High
None
None
Unchanged
High
High
None
Summary
Impact
Affected versions
Vulnerable code (file:line)
How an attacker reaches this code
Proof of concept (microbenchmark)Local Ruby microbenchmark isolating the verifier comparison path:
This isolates the same End-to-end reproduction against
| ||
11.2.1
patch
1 CVE
GHSA-mjgf-xj26-9qf9
Jul 01, 2026
pay-rails/pay: non-constant-time HMAC comparison in Paddle Billing webhook signature verifier
7.4
/ 10
High
Network
High
None
None
Unchanged
High
High
None
Summary
Impact
Affected versions
Vulnerable code (file:line)
How an attacker reaches this code
Proof of concept (microbenchmark)Local Ruby microbenchmark isolating the verifier comparison path:
This isolates the same End-to-end reproduction against
| ||
11.2.0
minor
1 CVE
GHSA-mjgf-xj26-9qf9
Jul 01, 2026
pay-rails/pay: non-constant-time HMAC comparison in Paddle Billing webhook signature verifier
7.4
/ 10
High
Network
High
None
None
Unchanged
High
High
None
Summary
Impact
Affected versions
Vulnerable code (file:line)
How an attacker reaches this code
Proof of concept (microbenchmark)Local Ruby microbenchmark isolating the verifier comparison path:
This isolates the same End-to-end reproduction against
| ||
11.1.3
patch
1 CVE
GHSA-mjgf-xj26-9qf9
Jul 01, 2026
pay-rails/pay: non-constant-time HMAC comparison in Paddle Billing webhook signature verifier
7.4
/ 10
High
Network
High
None
None
Unchanged
High
High
None
Summary
Impact
Affected versions
Vulnerable code (file:line)
How an attacker reaches this code
Proof of concept (microbenchmark)Local Ruby microbenchmark isolating the verifier comparison path:
This isolates the same End-to-end reproduction against
| ||
11.1.2
patch
1 CVE
GHSA-mjgf-xj26-9qf9
Jul 01, 2026
pay-rails/pay: non-constant-time HMAC comparison in Paddle Billing webhook signature verifier
7.4
/ 10
High
Network
High
None
None
Unchanged
High
High
None
Summary
Impact
Affected versions
Vulnerable code (file:line)
How an attacker reaches this code
Proof of concept (microbenchmark)Local Ruby microbenchmark isolating the verifier comparison path:
This isolates the same End-to-end reproduction against
| ||
11.1.1
patch
1 CVE
GHSA-mjgf-xj26-9qf9
Jul 01, 2026
pay-rails/pay: non-constant-time HMAC comparison in Paddle Billing webhook signature verifier
7.4
/ 10
High
Network
High
None
None
Unchanged
High
High
None
Summary
Impact
Affected versions
Vulnerable code (file:line)
How an attacker reaches this code
Proof of concept (microbenchmark)Local Ruby microbenchmark isolating the verifier comparison path:
This isolates the same End-to-end reproduction against
| ||
11.1.0
minor
1 CVE
GHSA-mjgf-xj26-9qf9
Jul 01, 2026
pay-rails/pay: non-constant-time HMAC comparison in Paddle Billing webhook signature verifier
7.4
/ 10
High
Network
High
None
None
Unchanged
High
High
None
Summary
Impact
Affected versions
Vulnerable code (file:line)
How an attacker reaches this code
Proof of concept (microbenchmark)Local Ruby microbenchmark isolating the verifier comparison path:
This isolates the same End-to-end reproduction against
| ||
11.0.1
patch
1 CVE
GHSA-mjgf-xj26-9qf9
Jul 01, 2026
pay-rails/pay: non-constant-time HMAC comparison in Paddle Billing webhook signature verifier
7.4
/ 10
High
Network
High
None
None
Unchanged
High
High
None
Summary
Impact
Affected versions
Vulnerable code (file:line)
How an attacker reaches this code
Proof of concept (microbenchmark)Local Ruby microbenchmark isolating the verifier comparison path:
This isolates the same End-to-end reproduction against
| ||
11.0.0
major
1 CVE
GHSA-mjgf-xj26-9qf9
Jul 01, 2026
pay-rails/pay: non-constant-time HMAC comparison in Paddle Billing webhook signature verifier
7.4
/ 10
High
Network
High
None
None
Unchanged
High
High
None
Summary
Impact
Affected versions
Vulnerable code (file:line)
How an attacker reaches this code
Proof of concept (microbenchmark)Local Ruby microbenchmark isolating the verifier comparison path:
This isolates the same End-to-end reproduction against
| ||
10.1.5
patch
1 CVE
GHSA-mjgf-xj26-9qf9
Jul 01, 2026
pay-rails/pay: non-constant-time HMAC comparison in Paddle Billing webhook signature verifier
7.4
/ 10
High
Network
High
None
None
Unchanged
High
High
None
Summary
Impact
Affected versions
Vulnerable code (file:line)
How an attacker reaches this code
Proof of concept (microbenchmark)Local Ruby microbenchmark isolating the verifier comparison path:
This isolates the same End-to-end reproduction against
| ||
10.1.4
patch
1 CVE
GHSA-mjgf-xj26-9qf9
Jul 01, 2026
pay-rails/pay: non-constant-time HMAC comparison in Paddle Billing webhook signature verifier
7.4
/ 10
High
Network
High
None
None
Unchanged
High
High
None
Summary
Impact
Affected versions
Vulnerable code (file:line)
How an attacker reaches this code
Proof of concept (microbenchmark)Local Ruby microbenchmark isolating the verifier comparison path:
This isolates the same End-to-end reproduction against
| ||
10.1.3
patch
1 CVE
GHSA-mjgf-xj26-9qf9
Jul 01, 2026
pay-rails/pay: non-constant-time HMAC comparison in Paddle Billing webhook signature verifier
7.4
/ 10
High
Network
High
None
None
Unchanged
High
High
None
Summary
Impact
Affected versions
Vulnerable code (file:line)
How an attacker reaches this code
Proof of concept (microbenchmark)Local Ruby microbenchmark isolating the verifier comparison path:
This isolates the same End-to-end reproduction against
| ||
10.1.2
patch
1 CVE
GHSA-mjgf-xj26-9qf9
Jul 01, 2026
pay-rails/pay: non-constant-time HMAC comparison in Paddle Billing webhook signature verifier
7.4
/ 10
High
Network
High
None
None
Unchanged
High
High
None
Summary
Impact
Affected versions
Vulnerable code (file:line)
How an attacker reaches this code
Proof of concept (microbenchmark)Local Ruby microbenchmark isolating the verifier comparison path:
This isolates the same End-to-end reproduction against
| ||
10.1.1
patch
1 CVE
GHSA-mjgf-xj26-9qf9
Jul 01, 2026
pay-rails/pay: non-constant-time HMAC comparison in Paddle Billing webhook signature verifier
7.4
/ 10
High
Network
High
None
None
Unchanged
High
High
None
Summary
Impact
Affected versions
Vulnerable code (file:line)
How an attacker reaches this code
Proof of concept (microbenchmark)Local Ruby microbenchmark isolating the verifier comparison path:
This isolates the same End-to-end reproduction against
| ||
10.1.0
minor
1 CVE
GHSA-mjgf-xj26-9qf9
Jul 01, 2026
pay-rails/pay: non-constant-time HMAC comparison in Paddle Billing webhook signature verifier
7.4
/ 10
High
Network
High
None
None
Unchanged
High
High
None
Summary
Impact
Affected versions
Vulnerable code (file:line)
How an attacker reaches this code
Proof of concept (microbenchmark)Local Ruby microbenchmark isolating the verifier comparison path:
This isolates the same End-to-end reproduction against
| ||
10.0.4
patch
1 CVE
GHSA-mjgf-xj26-9qf9
Jul 01, 2026
pay-rails/pay: non-constant-time HMAC comparison in Paddle Billing webhook signature verifier
7.4
/ 10
High
Network
High
None
None
Unchanged
High
High
None
Summary
Impact
Affected versions
Vulnerable code (file:line)
How an attacker reaches this code
Proof of concept (microbenchmark)Local Ruby microbenchmark isolating the verifier comparison path:
This isolates the same End-to-end reproduction against
| ||
10.0.3
patch
1 CVE
GHSA-mjgf-xj26-9qf9
Jul 01, 2026
pay-rails/pay: non-constant-time HMAC comparison in Paddle Billing webhook signature verifier
7.4
/ 10
High
Network
High
None
None
Unchanged
High
High
None
Summary
Impact
Affected versions
Vulnerable code (file:line)
How an attacker reaches this code
Proof of concept (microbenchmark)Local Ruby microbenchmark isolating the verifier comparison path:
This isolates the same End-to-end reproduction against
| ||
10.0.2
patch
1 CVE
GHSA-mjgf-xj26-9qf9
Jul 01, 2026
pay-rails/pay: non-constant-time HMAC comparison in Paddle Billing webhook signature verifier
7.4
/ 10
High
Network
High
None
None
Unchanged
High
High
None
Summary
Impact
Affected versions
Vulnerable code (file:line)
How an attacker reaches this code
Proof of concept (microbenchmark)Local Ruby microbenchmark isolating the verifier comparison path:
This isolates the same End-to-end reproduction against
| ||
10.0.1
patch
1 CVE
GHSA-mjgf-xj26-9qf9
Jul 01, 2026
pay-rails/pay: non-constant-time HMAC comparison in Paddle Billing webhook signature verifier
7.4
/ 10
High
Network
High
None
None
Unchanged
High
High
None
Summary
Impact
Affected versions
Vulnerable code (file:line)
How an attacker reaches this code
Proof of concept (microbenchmark)Local Ruby microbenchmark isolating the verifier comparison path:
This isolates the same End-to-end reproduction against
| ||
10.0.0
major
1 CVE
GHSA-mjgf-xj26-9qf9
Jul 01, 2026
pay-rails/pay: non-constant-time HMAC comparison in Paddle Billing webhook signature verifier
7.4
/ 10
High
Network
High
None
None
Unchanged
High
High
None
Summary
Impact
Affected versions
Vulnerable code (file:line)
How an attacker reaches this code
Proof of concept (microbenchmark)Local Ruby microbenchmark isolating the verifier comparison path:
This isolates the same End-to-end reproduction against
| ||
9.0.0
major
1 CVE
GHSA-mjgf-xj26-9qf9
Jul 01, 2026
pay-rails/pay: non-constant-time HMAC comparison in Paddle Billing webhook signature verifier
7.4
/ 10
High
Network
High
None
None
Unchanged
High
High
None
Summary
Impact
Affected versions
Vulnerable code (file:line)
How an attacker reaches this code
Proof of concept (microbenchmark)Local Ruby microbenchmark isolating the verifier comparison path:
This isolates the same End-to-end reproduction against
| ||
9.0.1
patch
1 CVE
GHSA-mjgf-xj26-9qf9
Jul 01, 2026
pay-rails/pay: non-constant-time HMAC comparison in Paddle Billing webhook signature verifier
7.4
/ 10
High
Network
High
None
None
Unchanged
High
High
None
Summary
Impact
Affected versions
Vulnerable code (file:line)
How an attacker reaches this code
Proof of concept (microbenchmark)Local Ruby microbenchmark isolating the verifier comparison path:
This isolates the same End-to-end reproduction against
| ||
8.3.0
minor
1 CVE
GHSA-mjgf-xj26-9qf9
Jul 01, 2026
pay-rails/pay: non-constant-time HMAC comparison in Paddle Billing webhook signature verifier
7.4
/ 10
High
Network
High
None
None
Unchanged
High
High
None
Summary
Impact
Affected versions
Vulnerable code (file:line)
How an attacker reaches this code
Proof of concept (microbenchmark)Local Ruby microbenchmark isolating the verifier comparison path:
This isolates the same End-to-end reproduction against
| ||
8.2.2
patch
1 CVE
GHSA-mjgf-xj26-9qf9
Jul 01, 2026
pay-rails/pay: non-constant-time HMAC comparison in Paddle Billing webhook signature verifier
7.4
/ 10
High
Network
High
None
None
Unchanged
High
High
None
Summary
Impact
Affected versions
Vulnerable code (file:line)
How an attacker reaches this code
Proof of concept (microbenchmark)Local Ruby microbenchmark isolating the verifier comparison path:
This isolates the same End-to-end reproduction against
| ||
8.2.1
patch
1 CVE
GHSA-mjgf-xj26-9qf9
Jul 01, 2026
pay-rails/pay: non-constant-time HMAC comparison in Paddle Billing webhook signature verifier
7.4
/ 10
High
Network
High
None
None
Unchanged
High
High
None
Summary
Impact
Affected versions
Vulnerable code (file:line)
How an attacker reaches this code
Proof of concept (microbenchmark)Local Ruby microbenchmark isolating the verifier comparison path:
This isolates the same End-to-end reproduction against
| ||
8.2.0
minor
1 CVE
GHSA-mjgf-xj26-9qf9
Jul 01, 2026
pay-rails/pay: non-constant-time HMAC comparison in Paddle Billing webhook signature verifier
7.4
/ 10
High
Network
High
None
None
Unchanged
High
High
None
Summary
Impact
Affected versions
Vulnerable code (file:line)
How an attacker reaches this code
Proof of concept (microbenchmark)Local Ruby microbenchmark isolating the verifier comparison path:
This isolates the same End-to-end reproduction against
| ||
8.1.3
patch
1 CVE
GHSA-mjgf-xj26-9qf9
Jul 01, 2026
pay-rails/pay: non-constant-time HMAC comparison in Paddle Billing webhook signature verifier
7.4
/ 10
High
Network
High
None
None
Unchanged
High
High
None
Summary
Impact
Affected versions
Vulnerable code (file:line)
How an attacker reaches this code
Proof of concept (microbenchmark)Local Ruby microbenchmark isolating the verifier comparison path:
This isolates the same End-to-end reproduction against
| ||
8.1.2
patch
1 CVE
GHSA-mjgf-xj26-9qf9
Jul 01, 2026
pay-rails/pay: non-constant-time HMAC comparison in Paddle Billing webhook signature verifier
7.4
/ 10
High
Network
High
None
None
Unchanged
High
High
None
Summary
Impact
Affected versions
Vulnerable code (file:line)
How an attacker reaches this code
Proof of concept (microbenchmark)Local Ruby microbenchmark isolating the verifier comparison path:
This isolates the same End-to-end reproduction against
| ||
8.1.1
patch
1 CVE
GHSA-mjgf-xj26-9qf9
Jul 01, 2026
pay-rails/pay: non-constant-time HMAC comparison in Paddle Billing webhook signature verifier
7.4
/ 10
High
Network
High
None
None
Unchanged
High
High
None
Summary
Impact
Affected versions
Vulnerable code (file:line)
How an attacker reaches this code
Proof of concept (microbenchmark)Local Ruby microbenchmark isolating the verifier comparison path:
This isolates the same End-to-end reproduction against
| ||
8.1.0
minor
1 CVE
GHSA-mjgf-xj26-9qf9
Jul 01, 2026
pay-rails/pay: non-constant-time HMAC comparison in Paddle Billing webhook signature verifier
7.4
/ 10
High
Network
High
None
None
Unchanged
High
High
None
Summary
Impact
Affected versions
Vulnerable code (file:line)
How an attacker reaches this code
Proof of concept (microbenchmark)Local Ruby microbenchmark isolating the verifier comparison path:
This isolates the same End-to-end reproduction against
| ||
8.0.0
major
1 CVE
GHSA-mjgf-xj26-9qf9
Jul 01, 2026
pay-rails/pay: non-constant-time HMAC comparison in Paddle Billing webhook signature verifier
7.4
/ 10
High
Network
High
None
None
Unchanged
High
High
None
Summary
Impact
Affected versions
Vulnerable code (file:line)
How an attacker reaches this code
Proof of concept (microbenchmark)Local Ruby microbenchmark isolating the verifier comparison path:
This isolates the same End-to-end reproduction against
| ||
7.3.0
minor
1 CVE
GHSA-mjgf-xj26-9qf9
Jul 01, 2026
pay-rails/pay: non-constant-time HMAC comparison in Paddle Billing webhook signature verifier
7.4
/ 10
High
Network
High
None
None
Unchanged
High
High
None
Summary
Impact
Affected versions
Vulnerable code (file:line)
How an attacker reaches this code
Proof of concept (microbenchmark)Local Ruby microbenchmark isolating the verifier comparison path:
This isolates the same End-to-end reproduction against
| ||
7.2.1
patch
1 CVE
GHSA-mjgf-xj26-9qf9
Jul 01, 2026
pay-rails/pay: non-constant-time HMAC comparison in Paddle Billing webhook signature verifier
7.4
/ 10
High
Network
High
None
None
Unchanged
High
High
None
Summary
Impact
Affected versions
Vulnerable code (file:line)
How an attacker reaches this code
Proof of concept (microbenchmark)Local Ruby microbenchmark isolating the verifier comparison path:
This isolates the same End-to-end reproduction against
| ||
7.2.0
minor
1 CVE
GHSA-mjgf-xj26-9qf9
Jul 01, 2026
pay-rails/pay: non-constant-time HMAC comparison in Paddle Billing webhook signature verifier
7.4
/ 10
High
Network
High
None
None
Unchanged
High
High
None
Summary
Impact
Affected versions
Vulnerable code (file:line)
How an attacker reaches this code
Proof of concept (microbenchmark)Local Ruby microbenchmark isolating the verifier comparison path:
This isolates the same End-to-end reproduction against
| ||
7.1.1
patch
1 CVE
GHSA-mjgf-xj26-9qf9
Jul 01, 2026
pay-rails/pay: non-constant-time HMAC comparison in Paddle Billing webhook signature verifier
7.4
/ 10
High
Network
High
None
None
Unchanged
High
High
None
Summary
Impact
Affected versions
Vulnerable code (file:line)
How an attacker reaches this code
Proof of concept (microbenchmark)Local Ruby microbenchmark isolating the verifier comparison path:
This isolates the same End-to-end reproduction against
| ||
7.1.0
minor
1 CVE
GHSA-mjgf-xj26-9qf9
Jul 01, 2026
pay-rails/pay: non-constant-time HMAC comparison in Paddle Billing webhook signature verifier
7.4
/ 10
High
Network
High
None
None
Unchanged
High
High
None
Summary
Impact
Affected versions
Vulnerable code (file:line)
How an attacker reaches this code
Proof of concept (microbenchmark)Local Ruby microbenchmark isolating the verifier comparison path:
This isolates the same End-to-end reproduction against
|