Known Vulnerabilities for Oauth2 by Ruby-oauth
Listed below are 10 of the newest known vulnerabilities associated with "Oauth2" by "Ruby-oauth".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-77069 json | n8n before 1.123.69, 2.33.4, and 2.34.1 contains an SSRF protection bypass in the OAuth2 credential authorization-code-to-acc... | Not Provided | 2026-08-20 | 2026-08-21 |
| CVE-2026-75866 json | Punk::OAuth2::Server versions through 0.03 for Perl issue access tokens outside a client's registered scopes and grant types ... | Not Provided | 2026-08-22 | 2026-08-22 |
| CVE-2026-75628 json | Punk::OAuth2 versions before 0.03 for Perl allow an attacker-chosen off-site redirect after login because same_origin_path ac... | Not Provided | 2026-08-20 | 2026-08-20 |
| CVE-2026-73308 json | Budibase is an open-source low-code platform. Prior to 3.39.25, packages/server/src/api/controllers/automation.ts returned au... | Not Provided | 2026-08-12 | 2026-08-14 |
| CVE-2026-73304 json | Budibase is an open-source low-code platform. Prior to 3.39.25, GET /api/users/metadata and GET /api/users/metadata/:id retur... | Not Provided | 2026-08-13 | 2026-08-14 |
| CVE-2026-70636 json | Flowise through 3.1.4 contains an authentication bypass vulnerability that allows unauthenticated attackers to access the OAu... | Not Provided | 2026-08-06 | 2026-08-08 |
| CVE-2026-70556 json | Hubzilla versions prior to 11.4 contains a cross-site request forgery vulnerability in the OAuth2 /authorize endpoint handle... | Not Provided | 2026-08-06 | 2026-08-13 |
| CVE-2026-70478 json | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the POST /api/v1/oau... | Not Provided | 2026-08-04 | 2026-08-05 |
| CVE-2026-70474 json | Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise h... | Not Provided | 2026-08-04 | 2026-08-05 |
| CVE-2026-69250 json | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the OAuth2 token ref... | Not Provided | 2026-08-04 | 2026-08-04 |