Ory
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 14 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from February 17, 2019 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →DOM-Based XSS in Ory Polis Login Page
Ory Keto has a SQL injection via forged pagination tokens
Ory Hydra has a SQL injection via forged pagination tokens
Ory Kratos has a SQL injection via forged pagination tokens
Ory Oathkeeper has a path traversal authorization bypass
Ory Oathkeeper has an authentication bypass by cache key confusion
Ory Oathkeeper has an authentication bypass by usage of untrusted header
Possible bypass of token claim validation when OAuth2 Introspection caching is enabled
OAuth2 Redirect URL validity does not respect query parameters and character casing for loopback addresses
Redirect URL matching ignores character casing
Monitor Ory in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.