Apifest maintains an OAuth 2.0 server implementation with a narrow product scope. The vendor's observed disclosures reflect a recurring pattern centered on URL-redirection flaws that permit attackers to redirect users to untrusted external sites, a weakness class endemic to authentication and authorization systems where redirect parameters must be strictly validated.
The number and severity of CVEs published that impact products developed by Apifest over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-26877MEDIUM ApiFest OAuth 2.0 Server 0.3.1 does not validate the redirect URI in accordance with RFC 6749 and is susceptible to an open redirector attack. Specifically, it directly sends an au | Jun 29, 2022 | 6.1 | 17 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Apifest.
Media articles that mention a CVE ID that affects a product developed by Apifest — matched by CVE ID, not by vendor name.