Please see https://github.com/omniauth/omniauth/pull/809 https://www.openwall.com/lists/oss-security/2015/05/26/11