Oauth
This hub aggregates every CVE we track for Oauth, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
OSS Librarieslibrary
6
CVEs tracked
0
Critical
3
High
0
In CISA KEV
Severity distribution
HIGH3MEDIUM3
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
2
0
2024-092026-08
Latest CVEs
The 6 most recently published vulnerabilities affecting Oauth.
- CVE-2026-54605OAuth: Cross-origin token-request redirects can expose signed request metadata7.2
- CVE-2026-13707Session fixation attacks on improperly configured OAuth 1.0a tools7.6
- CVE-2024-42476oauth CSRF vulnerability6.5
- CVE-2024-42475OAuth library for nim allows insecure generation of state values by generateState - entropy too low and uses regular PRNG instead of CSPRNG6.5
- CVE-2016-11086lib/oauth/consumer.rb in the oauth-ruby gem through 0.5.4 for Ruby does not verify server X.509 certificates if a certificate bundle cannot be found, which allows man-in-the-middle attackers to spo...7.4
- CVE-2017-9506The IconUriServlet of the Atlassian OAuth Plugin from version 1.3.0 before version 1.9.12 and from version 2.0.0 before version 2.0.4 allows remote attackers to access the content of internal netwo...6.1
Product normalization is registry-driven with AI assist and human review. How it works