@feathersjs/authentication-oauth
npm4 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting @feathersjs/authentication-oauthpage 1 of 1
- CVE-2026-27191MEDIUMCVSS 6.1EG 6.1✓ Fixed in 5.0.402026-02-21
Feathersjs is a framework for creating web APIs and real-time applications with TypeScript or JavaScript. Versions 5.0.39 and below the redirect query parameter is appended to the base origin without validation, allowing attackers to steal…
- CVE-2026-27192HIGHCVSS 8.1EG 8.1✓ Fixed in 5.0.402026-02-21
Feathersjs is a framework for creating web APIs and real-time applications with TypeScript or JavaScript. In versions 5.0.39 and below, origin validation uses startsWith() for comparison, allowing attackers to bypass the check by registeri…
- CVE-2026-27193MEDIUMCVSS 5.3EG 5.3✓ Fixed in 5.0.402026-02-21
Feathersjs is a framework for creating web APIs and real-time applications with TypeScript or JavaScript. In versions 5.0.39 and below, all HTTP request headers are stored in the session cookie, which is signed but not encrypted, exposing …
- CVE-2026-29792CRITICALCVSS 9.8EG 9.8✓ Fixed in 5.0.422026-03-10
Feathersjs is a framework for creating web APIs and real-time applications with TypeScript or JavaScript. From 5.0.0 to before 5.0.42, an unauthenticated attacker can send a crafted GET request directly to /oauth/:provider/callback with a …
Check whether @feathersjs/authentication-oauth is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for @feathersjs/authentication-oauth CVEs against the assets you own.
Start Free Scan →