Vulnerabilities

Summary — last 7 days

New vulnerabilities2,806▲ 5 vs. last week
Critical / high1,465▲ 246 vs. last week
New active exploitation (KEV)5▼ 5 vs. last week
Unscored (no CVSS)77▼ 441 vs. last week
–

52 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredMedium (6.3)0.69%—Ash-project ASH Authentication Oauth2 ServerAI9/7/20269/8/2026
Improper Authentication vulnerability in ash-project ash_authentication_oauth2_server allows an unauthenticated attacker to register OAuth clients even when Dynamic Client Registration is gated by an initial access token. resolve_secret/3 in AshAuthentication.Oauth2Server (reached through __resolve_secret__!) treated…
DeferredMedium (6.3)0.66%—Ash-project ASH Authentication Oauth2 ServerAI9/7/20269/8/2026
Server-Side Request Forgery (SSRF) vulnerability in ash-project ash_authentication_oauth2_server allows an attacker who controls a client metadata URL and its DNS to make the server connect to internal or loopback addresses. public_ip?/1 in AshAuthentication.Oauth2Server.CIMD.ReqFetcher enforces the outbound policy…
DeferredMedium (6.3)0.68%—Ash-project ASH Authentication Oauth2 ServerAI9/7/20269/8/2026
Improper Encoding or Escaping of Output vulnerability in ash-project ash_authentication_oauth2_server allows an unauthenticated attacker to inject arbitrary authentication parameters into the WWW-Authenticate challenge header. BearerPlug and RequireScopePlug built the Bearer resource_metadata="..." challenge by…
DeferredMedium (6.3)0.66%—Ash-project ASH Authentication Oauth2 ServerAI9/7/20269/8/2026
Use of Cache Containing Sensitive Information vulnerability in ash-project ash_authentication_oauth2_server allows a shared HTTP cache to serve one tenant's OAuth discovery metadata to another tenant's clients. The RFC 8414 and RFC 9728 metadata endpoints in AshAuthentication.Phoenix.Oauth2Server.ProtocolRouter return…
DeferredMedium (6.3)0.69%—Ash-project ASH Authentication Oauth2 ServerAI9/7/20269/8/2026
Improper Protection of Alternate Path vulnerability in ash-project ash_authentication_oauth2_server exposes the state-changing OAuth endpoints under an unintended URL prefix, bypassing controls scoped to the canonical prefix. oauth2_server_protocol_routes/1 in AshAuthentication.Phoenix.Oauth2Server.Router forwards the…
DeferredHigh (8.2)0.66%—Ash-project ASH Authentication Oauth2 ServerAI9/7/20269/8/2026
Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_authentication_oauth2_server allows an unauthenticated attacker to exhaust database storage and memory. The /authorize endpoint is unauthenticated by design. With Client ID Metadata Documents enabled, resolve_client/3 in…
DeferredCritical (9.3)0.45%—Oauth2 ProxyAI8/24/20269/24/2026
OAuth2 Proxy honours a client-supplied X-Forwarded-Uri header when deciding whether a request may skip authentication, because the guard added for CVE-2026-40575 is inert in the default reverse-proxy configuration. GetRequestURI in pkg/requests/util/util.go prefers that header over the real request URI whenever…
DeferredCritical (9.1)0.50%—Punk Oauth2 ServerAI8/22/20268/26/2026
Punk::OAuth2::Server versions through 0.03 for Perl issue access tokens outside a client's registered scopes and grant types because no authorization path reads them. Punk::OAuth2::Server::Store registers scopes and grant_types per client and documents both as client registration. token dispatches on the grant_type in…
DeferredMedium (5.7)0.50%—Punk Oauth2AI8/20/20268/28/2026
Punk::OAuth2 versions before 0.03 for Perl allow an attacker-chosen off-site redirect after login because same_origin_path accepts a backslash or tab in the return parameter. oauth2_login reads the return parameter from the initiation request, runs same_origin_path over it, and stores the survivor in the session flow…
AnalyzedMedium (5.4)0.10%—Fastify/oauth28/15/20269/4/2026
@fastify/oauth2 is an OAuth 2.0 plugin for Fastify. In versions from 7.2.0 up to but not including 8.3.0, the plugin validates the OAuth state, and with PKCE the code verifier, by comparing the callback query parameter against an unprefixed, predictable cookie, with no server-side binding to the browser that began the…
Awaiting AnalysisHigh (8.6)0.59%—Oauth2AI7/28/20269/9/2026
OAuth2 is a Ruby wrapper for the OAuth 2.0 and 2.1 authorization frameworks, including OpenID Connect (OIDC). From 0.4.0 to 2.0.21, a protocol-relative redirect Location returned to OAuth2::Client#request overrides the request authority, so the bearer Authorization header is sent to an attacker-controlled host,…
DeferredMedium (4.4)0.41%—Lockme Oauth2 Calendars IntegrationAI7/11/20267/13/2026
The Lockme OAuth2 calendars integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'App ID' setting in all versions up to, and including, 2.11.0. This is due to insufficient input sanitization and output escaping. The register_setting() call on line 197 lacks a sanitize callback,…
DeferredMedium (5.1)0.18%—Liboauth2AI7/2/20267/2/2026
In liboauth2 the Demonstrating Proof-of-Possession (DPoP) verifier accepts a proof whose JSON Web Key (jwk) header contains private key material. RFC 9449 section 4.3 step 7 requires the verifier to reject such a proof but oauth2_token_verify() function returns success for a malformed DPoP proof that embeds the…
DeferredMedium (5.1)0.17%—Liboauth2AI7/2/20267/2/2026
liboauth2 is vulnerable to Server-Side Request Forgery in oauth2_jose_jwks_aws_alb_resolve() function. The AWS ALB verifier reads both signer and kid from the unverified JWT header. If signer matches the configured ARN, kid is appended to alb_base_url without URL encoding or path sanitization, and the HTTP GET is…
DeferredCritical (9.1)0.52%—Mojolicious Plugin WEB Auth Oauth2AI6/23/20266/23/2026
Mojolicious::Plugin::Web::Auth::OAuth2 versions through 0.17 for Perl have an insecure default state parameter. When no state generator is specified in the constructor, the module defaults to using a SHA-1 hash of predictable and low-entropy sources, including the epoch time (which is leaked via the HTTP Date header)…
DeferredCritical (10)0.58%—Openvpn-auth-oauth2AI5/8/20266/17/2026
openvpn-auth-oauth2 is a plugin/management interface client for OpenVPN server to handle an OIDC based single sign-on (SSO) auth flows. From version 1.26.3 to before version 1.27.3, when openvpn-auth-oauth2 is deployed in the experimental plugin mode (shared library loaded by OpenVPN via the plugin directive), clients…
AnalyzedMedium (5.9)0.35%—Node-oauth/oauth2-server4/23/20266/17/2026
@node-oauth/oauth2-server is a module for implementing an OAuth2 server in Node.js. The token exchange path accepts RFC7636-invalid code_verifier values (including one-character strings) for S256 PKCE flows. Because short/weak verifiers are accepted and failed verifier attempts do not consume the authorization code,…
AnalyzedHigh (8.2)0.43%—Oauth2 Proxy Project Oauth2 Proxy4/22/20266/17/2026
OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions 7.5.0 through 7.15.1 have a configuration-dependent authentication bypass. Deployments are affected when all of the following are true: Use of `skip_auth_routes` or the legacy `skip_auth_regex`; use of patterns that can be…
ModifiedCritical (9.1)0.73%—Oauth2 Proxy Project Oauth2 Proxy4/22/20267/15/2026
OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions 7.5.0 through 7.15.1 may trust a client-supplied `X-Forwarded-Uri` header when `--reverse-proxy` is enabled and `--skip-auth-regex` or `--skip-auth-route` is configured. An attacker can spoof this header so OAuth2 Proxy…
AnalyzedMedium (6.8)0.34%—Oauth2 Proxy Project Oauth2 Proxy4/21/20266/17/2026
OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Prior to 7.15.2, an authorization bypass exists in OAuth2 Proxy as part of the email_domain enforcement option. An attacker may be able to authenticate with an email claim such as attacker@evil.com@company.com and satisfy an allowed…
AnalyzedCritical (9.1)0.66%—Oauth2 Proxy Project Oauth2 Proxy4/14/20267/24/2026
OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions prior to 7.15.2 contain a configuration-dependent authentication bypass in deployments where OAuth2 Proxy is used with an auth_request-style integration (such as nginx auth_request) and either --ping-user-agent is set or…
AnalyzedLow (3.5)0.22%—Oauth2 Proxy Project Oauth2 Proxy4/14/20267/24/2026
OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. A regression introduced in 7.11.0 prevents OAuth2 Proxy from clearing the session cookie when rendering the sign-in page. In deployments that rely on the sign-in page as part of their logout flow, a user may be shown the sign-in page…
DeferredHigh (8.5)0.62%—Oauth2 ProxyAI11/10/20256/17/2026
OAuth2-Proxy is an open-source tool that can act as either a standalone reverse proxy or a middleware component integrated into existing reverse proxy or load balancer setups. In versions prior to 7.13.0, all deployments of OAuth2 Proxy in front of applications that normalize underscores to dashes in HTTP headers…
AnalyzedCritical (9.1)1.2%—Oauth2 Proxy Project Oauth2 Proxy7/30/20256/17/2026
OAuth2-Proxy is an open-source tool that can act as either a standalone reverse proxy or a middleware component integrated into existing reverse proxy or load balancer setups. In versions 7.10.0 and below, oauth2-proxy deployments are vulnerable when using the skip_auth_routes configuration option with regex patterns.…
AnalyzedCritical (9.8)0.42%—Oauth2 Server Project Oauth2 Server3/31/20256/17/2026
Missing Authorization vulnerability in Drupal OAuth2 Server allows Forceful Browsing.This issue affects OAuth2 Server: from 0.0.0 before 2.1.0.