github.com/authorizerdev/authorizer
Go2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting github.com/authorizerdev/authorizerpage 1 of 1
- CVE-2026-35511HIGHEG not assessed✓ Fixed in 0.0.0-20260807033110-66fe488fd2a42026-08-14
Authorizer: Zero-click account takeover via OAuth identity linking to unverified email accounts The OAuth callback handler links incoming OAuth identities (Google, GitHub, etc.) to existing accounts matched by email address without verify…
- CVE-2026-54072CRITICALCVSS 9.3EG 9.3✓ Fixed in 0.0.0-20260409051328-bd3f5baf6d3d2026-07-10
Authorizer is an open-source, self-hostable authentication and authorization server. Prior to version 2.2.1, the `/authorize` endpoint accepts any `redirect_uri` without validating it against `AllowedOrigins`. When `response_type=token` or…
Check whether github.com/authorizerdev/authorizer is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for github.com/authorizerdev/authorizer CVEs against the assets you own.
Start Free Scan →