Ory develops a focused suite of identity, access control, and authorization infrastructure products—including Hydra, Kratos, Keto, OAuthkeeper, and Fosite—that serve as foundational components in authentication and permission-enforcement architectures. The vendor's vulnerability profile centers on input-handling and authentication-logic weaknesses including SQL injection, open-redirect conditions, improper input validation, and capture-replay and primary-weakness authentication bypasses, reflecting the parser and state-management demands of identity-layer software. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ory over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-33494CRITICAL ORY Oathkeeper is an Identity & Access Proxy (IAP) and Access Control Decision API that authorizes HTTP requests based on sets of Access Rules. Versions prior to 26.2.0 are vulnera | Mar 26, 2026 | 10.0 | 34 | NO | NO |
CVE-2026-33506HIGH Ory Polis, formerly known as BoxyHQ Jackson, bridges or proxies a SAML login flow to OAuth 2.0 or OpenID Connect. Versions prior to 26.2.0 contain a DOM-based Cross-Site Scripting | Mar 26, 2026 | 8.8 | 30 | NO | NO |
CVE-2026-33496HIGH ORY Oathkeeper is an Identity & Access Proxy (IAP) and Access Control Decision API that authorizes HTTP requests based on sets of Access Rules. Versions prior to 26.2.0 are vulner | Mar 26, 2026 | 8.1 | 28 | NO | NO |
CVE-2026-33505HIGH Ory Keto is am open source authorization server for managing permissions at scale. Prior to version 26.2.0, the GetRelationships API in Ory Keto is vulnerable to SQL injection due | Mar 26, 2026 | 7.2 | 25 | NO | NO |
CVE-2026-33504HIGH Ory Hydra is an OAuth 2.0 Server and OpenID Connect Provider. Prior to version 26.2.0, the listOAuth2Clients, listOAuth2ConsentSessions, and listTrustedOAuth2JwtGrantIssuers Admin | Mar 26, 2026 | 7.2 | 24 | NO | NO |
CVE-2021-32701HIGH ORY Oathkeeper is an Identity & Access Proxy (IAP) and Access Control Decision API that authorizes HTTP requests based on sets of Access Rules. When you make a request to an endpoi | Jun 22, 2021 | 7.5 | 24 | NO | NO |
CVE-2026-33503HIGH Ory Kratos is an identity, user management and authentication system for cloud services. Prior to version 26.2.0, the ListCourierMessages Admin API in Ory Kratos is vulnerable to S | Mar 26, 2026 | 7.2 | 23 | NO | NO |
CVE-2026-33495MEDIUM ORY Oathkeeper is an Identity & Access Proxy (IAP) and Access Control Decision API that authorizes HTTP requests based on sets of Access Rules. Ory Oathkeeper is often deployed beh | Mar 26, 2026 | 6.5 | 22 | NO | NO |
CVE-2019-8400MEDIUM ORY Hydra before v1.0.0-rc.3+oryOS.9 has Reflected XSS via the oauth2/fallbacks/error error_hint parameter. | Feb 17, 2019 | 6.1 | 21 | NO | NO |
CVE-2020-15223HIGH In ORY Fosite (the security first OAuth2 & OpenID Connect framework for Go) before version 0.34.0, the `TokenRevocationHandler` ignores errors coming from the storage. This can lea | Sep 24, 2020 | 8.0 | 20 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ory.
Media articles that mention a CVE ID that affects a product developed by Ory — matched by CVE ID, not by vendor name.