Authelia is a focused single-product authentication and authorization server that sits at the gateway layer to protect web applications and services, presenting a targeted but high-value attack surface. Its disclosed vulnerabilities center on authentication bypass, cross-site scripting, and open-redirect issues—weaknesses endemic to a credential-handling and redirect-heavy component—and defenders deploying this product should treat its security advisories as high-priority for the identity-layer role it occupies. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Authelia over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-32637CRITICAL Authelia is a a single sign-on multi-factor portal for web apps. This affects uses who are using nginx ngx_http_auth_request_module with Authelia, it allows a malicious individual | May 28, 2021 | 10.0 | 30 | NO | NO |
CVE-2026-33525MEDIUM Authelia is an open-source authentication and authorization server providing two-factor authentication and single sign-on (SSO) for applications via a web portal. In version 4.39.1 | Mar 26, 2026 | 6.1 | 21 | NO | NO |
CVE-2021-29456MEDIUM Authelia is an open-source authentication and authorization server providing 2-factor authentication and single sign-on (SSO) for your applications via a web portal. In versions 4. | Apr 21, 2021 | 5.4 | 18 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Authelia.
Media articles that mention a CVE ID that affects a product developed by Authelia — matched by CVE ID, not by vendor name.