Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Ory

First CVE: Feb 17, 2019Active for: 7 yearsTotal CVEs: 14
30.1
VTI Score
Low

Ory develops a focused suite of identity, access control, and authorization infrastructure products—including Hydra, Kratos, Keto, OAuthkeeper, and Fosite—that serve as foundational components in authentication and permission-enforcement architectures. The vendor's vulnerability profile centers on input-handling and authentication-logic weaknesses including SQL injection, open-redirect conditions, improper input validation, and capture-replay and primary-weakness authentication bypasses, reflecting the parser and state-management demands of identity-layer software. Live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
14
Total CVEs
More Total CVEs than 94% of tracked vendors
0.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 9% of tracked vendors
7.1
Avg CVSS Score
Higher Avg CVSS Score than 51% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Ory over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 17, 2019
7 years ago
Most Recent CVE
Mar 26, 2026
121 days ago

Products(6 total)

Top CVEs

Signals from CVEs in this vendor scope (14 CVEs).

14 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-33494CRITICAL
ORY Oathkeeper is an Identity & Access Proxy (IAP) and Access Control Decision API that authorizes HTTP requests based on sets of Access Rules. Versions prior to 26.2.0 are vulnera
Mar 26, 202610.034NONO
CVE-2026-33506HIGH
Ory Polis, formerly known as BoxyHQ Jackson, bridges or proxies a SAML login flow to OAuth 2.0 or OpenID Connect. Versions prior to 26.2.0 contain a DOM-based Cross-Site Scripting
Mar 26, 20268.830NONO
CVE-2026-33496HIGH
ORY Oathkeeper is an Identity & Access Proxy (IAP) and Access Control Decision API that authorizes HTTP requests based on sets of Access Rules. Versions prior to 26.2.0 are vulner
Mar 26, 20268.128NONO
CVE-2026-33505HIGH
Ory Keto is am open source authorization server for managing permissions at scale. Prior to version 26.2.0, the GetRelationships API in Ory Keto is vulnerable to SQL injection due
Mar 26, 20267.225NONO
CVE-2026-33504HIGH
Ory Hydra is an OAuth 2.0 Server and OpenID Connect Provider. Prior to version 26.2.0, the listOAuth2Clients, listOAuth2ConsentSessions, and listTrustedOAuth2JwtGrantIssuers Admin
Mar 26, 20267.224NONO
CVE-2021-32701HIGH
ORY Oathkeeper is an Identity & Access Proxy (IAP) and Access Control Decision API that authorizes HTTP requests based on sets of Access Rules. When you make a request to an endpoi
Jun 22, 20217.524NONO
CVE-2026-33503HIGH
Ory Kratos is an identity, user management and authentication system for cloud services. Prior to version 26.2.0, the ListCourierMessages Admin API in Ory Kratos is vulnerable to S
Mar 26, 20267.223NONO
CVE-2026-33495MEDIUM
ORY Oathkeeper is an Identity & Access Proxy (IAP) and Access Control Decision API that authorizes HTTP requests based on sets of Access Rules. Ory Oathkeeper is often deployed beh
Mar 26, 20266.522NONO
CVE-2019-8400MEDIUM
ORY Hydra before v1.0.0-rc.3+oryOS.9 has Reflected XSS via the oauth2/fallbacks/error error_hint parameter.
Feb 17, 20196.121NONO
CVE-2020-15223HIGH
In ORY Fosite (the security first OAuth2 & OpenID Connect framework for Go) before version 0.34.0, the `TokenRevocationHandler` ignores errors coming from the storage. This can lea
Sep 24, 20208.020NONO
View all 14 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products14 CVEs
36%
57%
Severity distribution among all CVEs352,427 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network14 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low12 (85.7%)
High2 (14.3%)
Unknown0 (0.0%)
User Interaction
None8 (57.1%)
Unknown0 (0.0%)
Required6 (42.9%)
Privileges Required
Low2 (14.3%)
High5 (35.7%)
None7 (50.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (14 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Ory.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Ory — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Ory's Products

View all 2 CNAs →

Top CWEs