ory has 7 CVEs on record between 2021 and 2024. The median CVSS is 7.5 (high). None have a confirmed exploitation report. Most affected products: github.com/ory/fosite (3), github.com/ory/oathkeeper (3), github.com/ory/hydra (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.5
- Publish → KEV
- —
- Last 90 days
- 0 prev 0
Products
- github.com/ory/fosite 3
- github.com/ory/oathkeeper 3
- github.com/ory/hydra 1
Worst active — by depth score
CVE-2020-15222High· 8.1Token reuse in Ory fosite45CVE-2020-15223High· 8.0Ory fosite contains Improper Handling of Exceptional Conditions 44GHSA-vfvf-6gx5-mqv6High· 7.5Incorrect Authorization in ORY Oathkeeper41GHSA-qvp4-rpmr-xwrrHigh· 7.5Possible bypass of token claim validation when OAuth2 Introspection caching is enabled41CVE-2020-15233Medium· 6.1OAuth2 Redirect URL validity does not respect query parameters and character casing for loopback addresses34
ory vulnerabilities
CVEs affecting ory, newest first. Open any entry for full detail, references, and exploit status.
7 CVEsRSS
GO-2022-0920NoneIncorrect Authorization in ORY Oathkeeper in github.com/ory/oathkeeper
Incorrect Authorization in ORY Oathkeeper in github.com/ory/oathkeeper
GHSA-vfvf-6gx5-mqv6High· 7.5Incorrect Authorization in ORY Oathkeeper
Incorrect Authorization in ORY Oathkeeper
GHSA-qvp4-rpmr-xwrrHigh· 7.5Possible bypass of token claim validation when OAuth2 Introspection caching is enabled
Possible bypass of token claim validation when OAuth2 Introspection caching is enabled
CVE-2020-5300Medium· 5.8Authentication Bypass in hydra
Authentication Bypass in hydra
CVE-2020-15223High· 8.0Ory fosite contains Improper Handling of Exceptional Conditions
Ory fosite contains Improper Handling of Exceptional Conditions
CVE-2020-15222High· 8.1Token reuse in Ory fosite
Token reuse in Ory fosite
CVE-2020-15233Medium· 6.1OAuth2 Redirect URL validity does not respect query parameters and character casing for loopback addresses
OAuth2 Redirect URL validity does not respect query parameters and character casing for loopback addresses