Known Vulnerabilities for Oauth2-server by Thephpleague
Listed below are 1 of the newest known vulnerabilities associated with "Oauth2-server" by "Thephpleague".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-81029 json | OpenMetadata accepts a caller-supplied post-authentication redirect target and appends the issued token to it. SamlLoginServl... | Not Provided | 2026-08-26 | 2026-08-26 |
| CVE-2026-75866 json | Punk::OAuth2::Server versions through 0.03 for Perl issue access tokens outside a client's registered scopes and grant types ... | Not Provided | 2026-08-22 | 2026-08-25 |
| CVE-2026-73308 json | Budibase is an open-source low-code platform. Prior to 3.39.25, packages/server/src/api/controllers/automation.ts returned au... | Not Provided | 2026-08-12 | 2026-08-14 |
| CVE-2026-73304 json | Budibase is an open-source low-code platform. Prior to 3.39.25, GET /api/users/metadata and GET /api/users/metadata/:id retur... | Not Provided | 2026-08-13 | 2026-08-14 |
| CVE-2026-70636 json | Flowise through 3.1.4 contains an authentication bypass vulnerability that allows unauthenticated attackers to access the OAu... | Not Provided | 2026-08-06 | 2026-08-14 |
| CVE-2026-69250 json | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the OAuth2 token ref... | Not Provided | 2026-08-04 | 2026-08-04 |
| CVE-2026-65594 json | n8n before 2.29.8 and 2.30.x before 2.30.1 (affected from 2.27.0, when the OAuth 2.1 consent and token-issuance flow was intr... | Not Provided | 2026-07-22 | 2026-07-23 |
| CVE-2026-61466 json | In Apache CXF's OAuth2 Dynamic Client Registration endpoint, the authorization server accepts and stores the `scope` value su... | Not Provided | 2026-08-06 | 2026-08-07 |
| CVE-2026-59822 json | LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, LiteLLM's MCP Streamab... | Not Provided | 2026-07-08 | 2026-09-03 |
| CVE-2026-59354 json | In versions of Spring Security's OAuth2 Authorization Server module 7.0.0 through 7.0.4, when Dynamic Client Registration is ... | Not Provided | 2026-08-27 | 2026-08-28 |