Known Vulnerabilities for Identity Provider by Internet2
Listed below are 1 of the newest known vulnerabilities associated with "Identity Provider" by "Internet2".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-73419 json | NextAuth.js provides authentication for Next.js. Prior to@auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, Auth.js s... | Not Provided | 2026-08-12 | 2026-08-13 |
| CVE-2026-73304 json | Budibase is an open-source low-code platform. Prior to 3.39.25, GET /api/users/metadata and GET /api/users/metadata/:id retur... | Not Provided | 2026-08-13 | 2026-08-14 |
| CVE-2026-73302 json | Budibase is an open-source low-code platform. Prior to 3.39.30, the OIDC flow in packages/backend-core/src/middleware/passpor... | Not Provided | 2026-08-13 | 2026-08-14 |
| CVE-2026-72561 json | A broken access control vulnerability in Peppermint Lab Peppermint through commit ba6e217 allows any authenticated non-admini... | Not Provided | 2026-08-11 | 2026-08-11 |
| CVE-2026-71327 json | Traefik is an open source HTTP reverse proxy and load balancer. From 3.0.0 until 3.6.25 and 3.7.10, Traefik's Kubernetes Gate... | Not Provided | 2026-08-06 | 2026-08-07 |
| CVE-2026-65655 json | When OAuth authentication is enabled and browser-facing TLS terminates at a reverse proxy that forwards the callback to Tempo... | Not Provided | 2026-08-11 | 2026-08-11 |
| CVE-2026-65602 json | Traefik 3.6.0 through 3.6.22 and 3.7.0 through 3.7.6 fail to enforce the crossProviderNamespaces allowlist for IngressRouteTC... | Not Provided | 2026-07-22 | 2026-07-24 |
| CVE-2026-65601 json | Traefik versions 3.7.0 through 3.7.6 contain a namespace confusion vulnerability in the Kubernetes Gateway API provider. When... | Not Provided | 2026-07-22 | 2026-07-24 |
| CVE-2026-57817 json | The OpenID Connect Core 1.0 specification mandates that the RP MUST validate the `c_hash` parameter when operating in the Hyb... | Not Provided | 2026-08-06 | 2026-08-07 |
| CVE-2026-56666 json | ZITADEL is an open source identity management platform. Prior to 4.15.3, ZITADEL's external identity provider handler checks ... | Not Provided | 2026-07-10 | 2026-07-13 |