Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

goauthentik — Vulnerabilities & Security Advisories 45

Browse all 45 CVE security advisories affecting goauthentik. AI-powered Chinese analysis, POCs, and references for each vulnerability.

goauthentik functions as an open-source identity provider, primarily serving as a self-hosted solution for single sign-on and identity governance. Its architecture supports complex authentication workflows, making it a critical component in enterprise access management strategies. Security audits have identified twenty-seven recorded Common Vulnerabilities and Exposures, reflecting the inherent risks of maintaining a complex, feature-rich identity platform. Historically, the most prevalent vulnerability classes include cross-site scripting and privilege escalation flaws, often stemming from improper input validation or insufficient access controls within its web interface. While no catastrophic, widespread data breaches have been publicly attributed to these specific CVEs, the high volume of findings indicates a need for rigorous patch management. The software’s open-source nature allows for community-driven security reviews, yet the frequency of issues suggests that continuous integration testing and code review processes remain essential for maintaining system integrity against potential exploitation.

Top products by goauthentik: authentik
CVE ID Title CVSS Severity Published
CVE-2024-47077 authentik cross-provider token validation problems — authentik CWE-863 6.5 Medium 2024-09-27
CVE-2024-47070 authentik vulnerable to password authentication bypass via X-Forwarded-For HTTP header — authentik CWE-287 9.1 Critical 2024-09-27
CVE-2024-42490 authentik has Insufficient Authorization for several API endpoints — authentik CWE-285 7.5 High 2024-08-22
CVE-2024-38371 Insufficient access control for OAuth2 Device Code flow in authentik — authentik CWE-284 8.6 High 2024-06-28
CVE-2024-37905 Improper Access Control and Incorrect Authorization in github.com/goauthentik/authentik — authentik CWE-284 8.8 High 2024-06-28
CVE-2024-23647 PKCE downgrade attack in Authentik — authentik CWE-287 6.5 Medium 2024-01-30
CVE-2024-21637 XSS in Authentik via JavaScript-URI as Redirect URI and form_post Response Mode — authentik CWE-79 7.7 High 2024-01-11
CVE-2023-48228 OAuth2: PKCE can be fully circumvented — authentik CWE-287 7.5 High 2023-11-21
CVE-2023-46249 authentik potential installation takeover when default admin user is deleted — authentik CWE-287 9.7 Critical 2023-10-31
CVE-2023-39522 Username enumeration attack in goauthentik — authentik CWE-203 5.3 Medium 2023-08-29
CVE-2023-36456 Authentik lacks Proxy IP headers validation — authentik CWE-436 8.3 High 2023-07-06
CVE-2023-26481 Insufficient user check in FlowTokens by Email stage — authentik CWE-345 9.1 Critical 2023-03-04
CVE-2022-46172 authentik allows existing authenticated users to create arbitrary accounts — authentik CWE-269 6.4 Medium 2022-12-28
CVE-2022-23555 authentik vulnerable to Improper Authentication via invitation URL token reuse — authentik CWE-287 9.4 Critical 2022-12-28
CVE-2022-46145 authentik vulnerable to unauthorized user creation and potential account takeover — authentik CWE-287 8.1 High 2022-12-02

This page lists every published CVE security advisory associated with goauthentik. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.