VendorsOryoathkeeperall versions
Vulnerabilities

Ory Oathkeeper

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2026-33494
Ory Oathkeeper has a path traversal authorization bypass
Published 2026-03-26 · Analyzed
10.0EPSS 0.006
CVE-2026-33496
Ory Oathkeeper has an authentication bypass by cache key confusion
Published 2026-03-26 · Analyzed
8.1EPSS 0.005
CVE-2021-32701
Possible bypass of token claim validation when OAuth2 Introspection caching is enabled
Published 2021-06-22 · Modified
7.5EPSS 0.016
CVE-2026-33495
Ory Oathkeeper has an authentication bypass by usage of untrusted header
Published 2026-03-26 · Analyzed
6.5EPSS 0.003