Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

ory — Vulnerabilities & Security Advisories 14

Browse all 14 CVE security advisories affecting ory. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Ory provides open-source identity and access management solutions, including authentication, authorization, and user management services. Historically, the project has faced vulnerabilities across multiple classes, including remote code execution, cross-site scripting, privilege escalation, and insecure direct object references. Notable security characteristics include its cloud-native architecture and OAuth 2.0/OpenID Connect implementations. While no major public security incidents have been widely reported, the project maintains a moderate CVE count with 14 recorded vulnerabilities to date, primarily related to input validation and access control issues in its core authentication flows.

CVE ID Title CVSS Severity Published
CVE-2026-33506 DOM-Based XSS in Ory Polis Login Page — polis CWE-87 8.8 High 2026-03-26
CVE-2026-33505 Ory Keto has a SQL injection via forged pagination tokens — keto CWE-89 7.2 High 2026-03-26
CVE-2026-33504 Ory Hydra has a SQL injection via forged pagination tokens — hydra CWE-89 7.2 High 2026-03-26
CVE-2026-33503 Ory Kratos has a SQL injection via forged pagination tokens — kratos CWE-89 7.2 High 2026-03-26
CVE-2026-33496 Ory Oathkeeper has an authentication bypass by cache key confusion — oathkeeper CWE-1289 8.1 High 2026-03-26
CVE-2026-33495 Ory Oathkeeper has an authentication bypass by usage of untrusted header — oathkeeper CWE-862 6.5 Medium 2026-03-26
CVE-2026-33494 Ory Oathkeeper has a path traversal authorization bypass — oathkeeper CWE-23 10.0 Critical 2026-03-26
CVE-2024-45042 Ory Kratos's `highest_available` setting does not properly respect code + mfa credentials — kratos CWE-287 4.4 Medium 2024-09-26
CVE-2021-32701 Possible bypass of token claim validation when OAuth2 Introspection caching is enabled — oathkeeper CWE-863 7.5 High 2021-06-22
CVE-2020-15233 OAuth2 Redirect URL validity does not respect query parameters and character casing for loopback addresses — fosite CWE-20 6.1 Medium 2020-10-02
CVE-2020-15234 Redirect URL matching ignores character casing — fosite CWE-20 6.1 Medium 2020-10-02
CVE-2020-15222 Replay of private_key_jwt possible in ORY Fosite — fosite CWE-287 8.1 High 2020-09-24
CVE-2020-15223 Ignored storage errors on token revokation in ORY Fosite — fosite CWE-755 8.0 High 2020-09-24
CVE-2020-5300 Disallow replay of `private_key_jwt` by blacklisting JTIs in Hydra — hydra CWE-294 5.8 Medium 2020-04-06

This page lists every published CVE security advisory associated with ory. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.