Incorrect Authorization Affecting github.com/dexidp/dex/server package, versions >=2.45.1


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Incorrect Authorization vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-GOLANG-GITHUBCOMDEXIDPDEXSERVER-17279480
  • published10 Jun 2026
  • disclosed9 Jun 2026
  • creditMatteo Panzeri

Introduced: 9 Jun 2026

CVE NOT AVAILABLE CWE-863  (opens in a new tab)

How to fix?

A fix was pushed into the master branch but not yet published.

Overview

Affected versions of this package are vulnerable to Incorrect Authorization in the handleTokenExchange() function. An attacker can gain unauthorized access to restricted resources by exploiting the lack of enforcement of allowed connectors when exchanging tokens. This is only exploitable if an attacker obtains a valid client secret for a client that is configured to restrict allowed connectors and also possesses a valid identity token from a connector that should not be permitted.

CVSS Base Scores

version 4.0
version 3.1