Pomerium develops an identity and access management proxy that sits inline to authorize and route user requests to protected applications, a role that places authentication and authorization logic at the center of its threat model. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity, and recur through weakness classes including incorrect authorization logic, URL redirection flaws, and sensitive-information exposure that are characteristic of identity-layer intermediaries. Defenders should prioritize this vendor's security advisories given the privileged position of proxy infrastructure in access control; live severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pomerium over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-24797CRITICAL Pomerium is an identity-aware access proxy. In distributed service mode, Pomerium's Authenticate service exposes pprof debug and prometheus metrics handlers to untrusted traffic. T | Mar 31, 2022 | 9.1 | 29 | NO | NO |
CVE-2023-33189CRITICAL Pomerium is an identity and context-aware access proxy. With specially crafted requests, incorrect authorization decisions may be made by Pomerium. This issue has been patched in v | May 30, 2023 | 9.8 | 28 | NO | NO |
CVE-2021-41230HIGH Pomerium is an open source identity-aware access proxy. In affected versions changes to the OIDC claims of a user after initial login are not reflected in policy evaluation when us | Nov 5, 2021 | 8.8 | 27 | NO | NO |
CVE-2021-39206HIGH Pomerium is an open source identity-aware access proxy. Envoy, which Pomerium is based on, contains two authorization related vulnerabilities CVE-2021-32777 and CVE-2021-32779. Thi | Sep 9, 2021 | 8.6 | 27 | NO | NO |
CVE-2021-39162HIGH Pomerium is an open source identity-aware access proxy. Envoy, which Pomerium is based on, can abnormally terminate if an H/2 GOAWAY and SETTINGS frame are received in the same IO | Sep 9, 2021 | 8.6 | 26 | NO | NO |
CVE-2021-39204HIGH Pomerium is an open source identity-aware access proxy. Envoy, which Pomerium is based on, incorrectly handles resetting of HTTP/2 streams with excessive complexity. This can lead | Sep 9, 2021 | 7.5 | 25 | NO | NO |
CVE-2024-39315MEDIUM Pomerium is an identity and context-aware access proxy. Prior to version 0.26.1, the Pomerium user info page (at `/.pomerium`) unintentionally included serialized OAuth2 access and | Jul 2, 2024 | 6.5 | 20 | NO | NO |
CVE-2021-29652MEDIUM Pomerium from version 0.10.0-0.13.3 has an Open Redirect in the user sign-in/out process | Apr 2, 2021 | 6.1 | 20 | NO | NO |
CVE-2021-29651MEDIUM Pomerium before 0.13.4 has an Open Redirect (issue 1 of 2). | Apr 2, 2021 | 6.1 | 18 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pomerium.
Media articles that mention a CVE ID that affects a product developed by Pomerium — matched by CVE ID, not by vendor name.