Skip to content
Noroxi

ory records

14 published records for vendor ory.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
92.9%
Median publish → KEV
No record has entered KEV

All records

14 records
  • Ory Oathkeeper has a path traversal authorization bypass

    CriticalCVSS 10.0No exploitEPSS 1%

    ory · oathkeeperMar 26, 2026

  • DOM-Based XSS in Ory Polis Login Page

    HighCVSS 8.8No exploitEPSS 0%

    ory · polisMar 26, 2026

  • Ignored storage errors on token revokation in ORY Fosite

    HighCVSS 8.0No exploitEPSS 2%

    ory · fositeSep 24, 2020

  • Replay of private_key_jwt possible in ORY Fosite

    HighCVSS 8.1No exploitEPSS 1%

    ory · fositeSep 24, 2020

  • Ory Oathkeeper has an authentication bypass by cache key confusion

    HighCVSS 8.1No exploitEPSS 1%

    ory · oathkeeperMar 26, 2026

  • Possible bypass of token claim validation when OAuth2 Introspection caching is enabled

    HighCVSS 7.5No exploitEPSS 2%

    ory · oathkeeperJun 22, 2021

  • Ory Hydra has a SQL injection via forged pagination tokens

    HighCVSS 7.2No exploitEPSS 0%

    ory · hydraMar 26, 2026

  • Ory Kratos has a SQL injection via forged pagination tokens

    HighCVSS 7.2No exploitEPSS 0%

    ory · kratosMar 26, 2026

  • Ory Keto has a SQL injection via forged pagination tokens

    HighCVSS 7.2No exploitEPSS 0%

    ory · ketoMar 26, 2026

  • Ory Oathkeeper has an authentication bypass by usage of untrusted header

    MediumCVSS 6.5No exploitEPSS 0%

    ory · oathkeeperMar 26, 2026

  • CVE-2019-8400
    24Monitor

    ORY Hydra before v1.0.0-rc.3+oryOS.9 has Reflected XSS via the oauth2/fallbacks/error error_hint parameter.

    MediumCVSS 6.1No exploitEPSS 1%

    ory · hydraFeb 17, 2019

  • CVE-2020-5300
    21Monitor

    Disallow replay of `private_key_jwt` by blacklisting JTIs in Hydra

    MediumCVSS 5.3No exploitEPSS 1%

    ory · hydraApr 6, 2020

  • Redirect URL matching ignores character casing

    MediumCVSS 4.8No exploitEPSS 1%

    ory · fositeOct 2, 2020

  • OAuth2 Redirect URL validity does not respect query parameters and character casing for loopback addresses

    MediumCVSS 4.8No exploitEPSS 1%

    ory · fositeOct 2, 2020