Repository navigation
Security: authorizerdev/authorizer
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
required_relations gate evaluates a machine token against a user subjectGHSA-cvhv-hmq5-59gq published
Sep 3, 2026 by lakhansamaniHigh -
Admin-secret brute-force lockout bypassed by deriving the client IP from untrusted inputGHSA-93hc-xq3w-xw87 published
Sep 3, 2026 by lakhansamaniCritical -
RFC 8693 token exchange launders a service account's machine identity into a user identityGHSA-vq29-8q3c-3hrm published
Sep 3, 2026 by lakhansamaniHigh -
TOTP recovery codes are not single-use under concurrency, allowing one code to bypass MFA repeatedlyGHSA-xc9v-r84m-4qx9 published
Aug 13, 2026 by lakhansamaniModerate -
Social-login state parameter injection lets a caller forge the callback redirect URI and assigned rolesGHSA-fxxg-mx7x-3rx8 published
Aug 13, 2026 by lakhansamaniModerate -
SSRF guard bypass via IPv6 transition addresses (NAT64/6to4/Teredo) in webhook and OIDC endpoint validationGHSA-qxfq-3qvw-w5fr published
Aug 14, 2026 by lakhansamaniHigh -
Password Reset Poisoning via Host Header InjectionGHSA-m82j-rq33-qjx2 published
Aug 14, 2026 by lakhansamaniHigh -
redirect_uri / CORS origin allowlist bypass via unescaped regex dots — incomplete fix of GHSA-x3f4-v83f-7wp2GHSA-89vc-q979-qwxv published
Aug 14, 2026 by lakhansamaniHigh -
Unauthenticated privilege escalation via signup roles parameter (bypass of --protected-roles)GHSA-845v-5ggv-pwfp published
Aug 13, 2026 by lakhansamaniCritical -
Timing Attack in Login ValidationGHSA-c2mx-6qjh-6ppj published
Aug 13, 2026 by lakhansamaniHigh