PatchSiren

authorizerdev CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL authorizerdev CVE published 2026-09-11

CVE-2026-54072

CVE-2026-54072 is a critical vulnerability in the Authorizer open-source authentication and authorization server. The `/authorize` endpoint accepts any `redirect_uri` without validation, allowing an unauthenticated attacker to obtain sensitive tokens via a 302 redirect. A partial fix was applied in v2.0.1 but was not complete until v2.2.1. This vulnerability allows token leakage via redirect_uri manipulat [truncated]