Oauth2-server
This hub aggregates every CVE we track for Oauth2-server, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
3
CVEs tracked
0
Critical
3
High
0
In CISA KEV
Severity distribution
HIGH3
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
2024-102026-09
Latest CVEs
The 3 most recently published vulnerabilities affecting Oauth2-server.
- CVE-2023-37260league/oauth2-server key exposed in exception message when passing as string and providing invalid pass phrase8.2
- CVE-2020-26938In oauth2-server (aka node-oauth2-server) through 3.1.1, the value of the redirect_uri parameter received during the authorization and token request is checked against an incorrect URI pattern ("[a...7.2
- CVE-2017-18924oauth2-server (aka node-oauth2-server) through 3.1.1 implements OAuth 2.0 without PKCE. It does not prevent authorization code injection. This is similar to CVE-2020-7692. NOTE: the vendor states '...7.5
Product normalization is registry-driven with AI assist and human review. How it works