Known Vulnerabilities for Oauth2 by Ruby-oauth
Listed below are 10 of the newest known vulnerabilities associated with "Oauth2" by "Ruby-oauth".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-102616 json | A vulnerability was detected in risesoft-y9 WorkFlow-Engine up to 9.6.10. Impacted is the function getByIdAndYear of the file... | Not Provided | 2026-09-29 | 2026-09-29 |
| CVE-2026-101322 json | In Eclipse BaSyx AAS Web UI versions v2-241220 through releases before v2-260924, the shared request handler attached the sel... | Not Provided | 2026-10-01 | 2026-10-01 |
| CVE-2026-101090 json | Nezha 2.2.3 contains a Host header injection regression in the OAuth2 redirect endpoint. When the new optional dashboard_host... | Not Provided | 2026-09-27 | 2026-09-28 |
| CVE-2026-101059 json | utcp-http before 1.1.4 fails to validate the OAuth2 tokenUrl field from remote OpenAPI specifications, allowing attackers to ... | Not Provided | 2026-09-27 | 2026-09-28 |
| CVE-2026-101057 json | utcp-mcp (the MCP plugin of python-utcp) through 1.1.2 connects to the HTTP and WebSocket MCP server URLs given in a call tem... | Not Provided | 2026-09-27 | 2026-09-30 |
| CVE-2026-97325 json | A security flaw has been discovered in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. Affected by this vulnerability is th... | Not Provided | 2026-09-24 | 2026-09-25 |
| CVE-2026-92288 json | Lemonldap::NG::Portal versions from 2.20.0 before 2.21.6, from 2.22.0 before 2.23.4 for Perl allow unauthenticated OAuth2 tok... | Not Provided | 2026-09-25 | 2026-09-25 |
| CVE-2026-91039 json | Authentication Bypass by Spoofing vulnerability in team-alembic ash_authentication allows an attacker who operates one identi... | Not Provided | 2026-09-17 | 2026-09-17 |
| CVE-2026-88952 json | Improper Authentication vulnerability in team-alembic AshAuthentication allows an attacker to be signed in as another user by... | Not Provided | 2026-09-17 | 2026-09-17 |
| CVE-2026-85511 json | A flaw was found in EAP's Elytron. An EAP application whose security domain is backed by an Elytron token-realm with oauth2-i... | Not Provided | 2026-09-18 | 2026-09-25 |