Vulnerability index

Browse CVEs

12 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Polis HIGH 8.8
CVE-2026-33506

Ory Polis, formerly known as BoxyHQ Jackson, bridges or proxies a SAML login flow to OAuth 2.0 or OpenID Connect. Versions prior to 26.2.0 contain a …

Fix: 26.2.0+
Fix from $1,950 2026-03-26
Keto HIGH 7.2
CVE-2026-33505

Ory Keto is am open source authorization server for managing permissions at scale. Prior to version 26.2.0, the GetRelationships API in Ory Keto is v…

Fix: 26.2.0+
Fix from $1,950 2026-03-26
Hydra HIGH 7.2
CVE-2026-33504

Ory Hydra is an OAuth 2.0 Server and OpenID Connect Provider. Prior to version 26.2.0, the listOAuth2Clients, listOAuth2ConsentSessions, and listTrus…

Fix: 26.2.0+
Fix from $1,950 2026-03-26
Oathkeeper CRITICAL 10.0
CVE-2026-33494

ORY Oathkeeper is an Identity & Access Proxy (IAP) and Access Control Decision API that authorizes HTTP requests based on sets of Access Rules. Versi…

Fix: 26.2.0+
Fix from $2,300 2026-03-26
Oathkeeper HIGH 8.1
CVE-2026-33496

ORY Oathkeeper is an Identity & Access Proxy (IAP) and Access Control Decision API that authorizes HTTP requests based on sets of Access Rules. Versi…

Fix: 26.2.0+
Fix from $1,950 2026-03-26
Kratos HIGH 7.2
CVE-2026-33503

Ory Kratos is an identity, user management and authentication system for cloud services. Prior to version 26.2.0, the ListCourierMessages Admin API i…

Fix: 26.2.0+
Fix from $1,950 2026-03-26
Oathkeeper MEDIUM 6.5
CVE-2026-33495

ORY Oathkeeper is an Identity & Access Proxy (IAP) and Access Control Decision API that authorizes HTTP requests based on sets of Access Rules. Ory O…

Fix: 26.2.0+
Fix from $1,600 2026-03-26
Oathkeeper HIGH 7.5
CVE-2021-32701

ORY Oathkeeper is an Identity & Access Proxy (IAP) and Access Control Decision API that authorizes HTTP requests based on sets of Access Rules. When …

Patch available
Fix from $1,950 2021-06-22
Fosite HIGH 8.1
CVE-2020-15222

In ORY Fosite (the security first OAuth2 & OpenID Connect framework for Go) before version 0.31.0, when using "private_key_jwt" authentication the un…

Fix: 0.31.0+
Fix from $1,950 2020-09-24
Fosite HIGH 8.0
CVE-2020-15223

In ORY Fosite (the security first OAuth2 & OpenID Connect framework for Go) before version 0.34.0, the `TokenRevocationHandler` ignores errors coming…

Fix: 0.34.0+
Fix from $1,950 2020-09-24
Hydra MEDIUM 5.3
CVE-2020-5300

In Hydra (an OAuth2 Server and OpenID Certified™ OpenID Connect Provider written in Go), before version 1.4.0+oryOS.17, when using client authenticat…

Fix: 1.4.0+
Fix from $1,600 2020-04-06
Hydra MEDIUM 6.1
CVE-2019-8400

ORY Hydra before v1.0.0-rc.3+oryOS.9 has Reflected XSS via the oauth2/fallbacks/error error_hint parameter.

Patch available
Fix from $1,600 2019-02-17