CVE-2026-33494

Source
https://cve.org/CVERecord?id=CVE-2026-33494
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-33494.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-33494
Aliases
Downstream
Related
Published
2026-03-26T17:23:33.108Z
Modified
2026-04-10T05:43:17.071178Z
Severity
  • 10.0 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N CVSS Calculator
Summary
Ory Oathkeeper has a path traversal authorization bypass
Details

ORY Oathkeeper is an Identity & Access Proxy (IAP) and Access Control Decision API that authorizes HTTP requests based on sets of Access Rules. Versions prior to 26.2.0 are vulnerable to an authorization bypass via HTTP path traversal. An attacker can craft a URL containing path traversal sequences (e.g. /public/../admin/secrets) that resolves to a protected path after normalization, but is matched against a permissive rule because the raw, un-normalized path is used during rule evaluation. Version 26.2.0 contains a patch.

Database specific
{
    "cwe_ids": [
        "CWE-23"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/33xxx/CVE-2026-33494.json",
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/ory/oathkeeper

Affected ranges

Type
GIT
Repo
https://github.com/ory/oathkeeper
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "fixed": "26.2.0"
        }
    ]
}

Affected versions

v0.*
v0.0.1
v0.0.10
v0.0.11
v0.0.12
v0.0.13
v0.0.14
v0.0.15
v0.0.16
v0.0.17
v0.0.18
v0.0.19
v0.0.2
v0.0.20
v0.0.21
v0.0.22
v0.0.23
v0.0.24
v0.0.25
v0.0.26
v0.0.27
v0.0.28
v0.0.29
v0.0.3
v0.0.4
v0.0.5
v0.0.6
v0.0.7
v0.0.8
v0.0.9
v0.11.12
v0.14.0+oryOS.10
v0.14.1+oryOS.10
v0.14.2+oryOS.10
v0.15.0
v0.15.1
v0.15.2
v0.16.0-beta.3
v0.16.0-beta.4
v0.16.0-beta.5
v0.17.0-beta.1
v0.17.1-beta.1
v0.17.2-beta.1
v0.17.3-beta.1
v0.17.4-beta.1
v0.18.0-beta.1
v0.19.0-beta.1
v0.31.0-beta.1
v0.32.0-beta.1
v0.32.1-beta.1
v0.33.0-beta.1
v0.33.1-beta.1
v0.34.0-beta.1
v0.35.0-alpha.1
v0.35.0-beta.1
v0.35.1-beta.1
v0.35.3-beta.1
v0.35.4-beta.1
v0.35.5-beta.1
v0.35.5-beta.2
v0.36.0-beta.1
v0.36.0-beta.2
v0.36.0-beta.3
v0.36.0-beta.4
v0.37.0-beta.1
v0.37.1-beta.1
v0.38.0-beta.2
v0.38.1-beta.1
v0.38.10-beta.2
v0.38.11-beta.1
v0.38.12-beta.1
v0.38.14-beta.1
v0.38.15-beta.1
v0.38.17-beta.1
v0.38.18-beta.1
v0.38.19-beta.1
v0.38.2-beta.1
v0.38.20-beta.1
v0.38.22-beta.1
v0.38.23-beta.1
v0.38.24-beta.1
v0.38.25-beta.1
v0.38.3-beta.1
v0.38.4-beta.1
v0.38.5-beta.1
v0.38.6-beta.1
v0.38.7-beta.1
v0.38.8-beta.1
v0.38.9-beta.1
v0.38.9-beta.1.pre.1
v0.38.9-beta.1.pre.2
v0.38.9-beta.1.pre.3
v0.39.0
v0.39.2
v0.39.3
v0.39.3-pre.0
v0.39.4
v0.40.0
v0.40.1
v0.40.2
v0.40.3
v0.40.4
v0.40.5
v0.40.6
v0.40.7
v0.40.7-pre.0
v0.40.8
v0.40.9
v25.*
v25.4.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-33494.json"