cbcvebase.

Goauthentik Authentik vulnerabilities

45 known vulnerabilities affecting goauthentik/authentik.

Total CVEs
45
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL10HIGH24MEDIUM11

Vulnerabilities

Page 3 of 3
CVE-2023-39522P4MEDIUMCVSS 5.3fixed in 2023.5.6≥ 2023.6.0, < 2023.6.2+1 more2023-08-29
CVE-2023-39522 [MEDIUM] CWE-203 CVE-2023-39522: goauthentik is an open-source Identity Provider. In affected versions using a recovery flow with an goauthentik is an open-source Identity Provider. In affected versions using a recovery flow with an identification stage an attacker is able to determine if a username exists. Only setups configured with a recovery flow are impacted by this. Anyone with a user account on a system with the recovery flow described above is susceptible to having their u
nvd
CVE-2025-64708P4MEDIUMCVSS 5.3≥ 2025.8.0, < 2025.8.5≥ 2025.10.0, < 2025.10.2+2 more2025-11-19
CVE-2025-64708 [MEDIUM] CWE-613 CVE-2025-64708: authentik is an open-source Identity Provider. Prior to versions 2025.8.5 and 2025.10.2, in previous authentik is an open-source Identity Provider. Prior to versions 2025.8.5 and 2025.10.2, in previous authentik versions, invitations were considered valid regardless if they are expired or not, thus relying on background tasks to clean up expired ones. In a normal scenario this can take up to 5 minutes because the cleanup of expired objects is sched
nvd
CVE-2024-21637P4MEDIUMCVSS 5.4≥ 2023.8.0, < 2023.8.6≥ 2023.10.0, < 2023.10.6+1 more2024-01-11
CVE-2024-21637 [MEDIUM] CWE-79 CVE-2024-21637: Authentik is an open-source Identity Provider. Authentik is a vulnerable to a reflected Cross-Site S Authentik is an open-source Identity Provider. Authentik is a vulnerable to a reflected Cross-Site Scripting vulnerability via JavaScript-URIs in OpenID Connect flows with `response_mode=form_post`. This relatively user could use the described attacks to perform a privilege escalation. This vulnerability has been patched in versions 2023.10.6 and 202
nvd
CVE-2025-64521P4MEDIUMCVSS 4.8≥ 2025.8.0, < 2025.8.5≥ 2025.10.0, < 2025.10.2+2 more2025-11-19
CVE-2025-64521 [MEDIUM] CWE-289 CVE-2025-64521: authentik is an open-source Identity Provider. Prior to versions 2025.8.5 and 2025.10.2, when authen authentik is an open-source Identity Provider. Prior to versions 2025.8.5 and 2025.10.2, when authenticating with client_id and client_secret to an OAuth provider, authentik creates a service account for the provider. In previous authentik versions, authentication for this account was possible even when the account was deactivated. Other permissions
nvd
CVE-2024-11623P4MEDIUMCVSS 4.8fixed in 2024.10.42025-02-04
CVE-2024-11623 [MEDIUM] CWE-79 CVE-2024-11623: Authentik project is vulnerable to Stored XSS attacks through uploading crafted SVG files that are u Authentik project is vulnerable to Stored XSS attacks through uploading crafted SVG files that are used as application icons. This action could only be performed by an authenticated admin user. The issue was fixed in 2024.10.4 release.
nvd
Goauthentik Authentik vulnerabilities | cvebase