github.com/pomerium/pomerium
Pomerium is an identity and context-aware access proxy.
Activity
- Latest release
- 4d ago
- Total releases
- 68
- Cadence
- ~22 days
- Last 12 months
- 21
Reach
- Stars
- 5.0k
Details
- First release
- Feb 19, 2019
| Version | Released | |
|---|---|---|
v0.33.3
patch
|
v0.33.3
patch
Dependencies (145)
+ 137 more |
|
v0.33.2
patch
|
v0.33.2
patch
Dependencies (145)
+ 137 more |
|
v0.33.1
patch
|
v0.33.1
patch
Dependencies (145)
+ 137 more |
|
v0.33.0
minor
|
v0.33.0
minor
Dependencies (145)
+ 137 more |
|
v0.32.9
patch
|
v0.32.9
patch
Dependencies (122)
+ 114 more |
|
v0.32.8
patch
|
v0.32.8
patch
Dependencies (122)
+ 114 more |
|
v0.32.7
patch
1 CVE
CVE-2026-50285
GHSA-ggw3-5987-rx77
Jul 15, 2026
Pomerium Pre-Auth Memory Exhaustion via Unbounded zstd Decompression in HPKE Callback
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryThe HPKE V2 URL decode path in SeverityHigh (CVSS 3.1: 7.5)
Affected Component
CWE
DescriptionUnbounded zstd Decompression in
|
v0.32.7
patch
Dependencies (122)
+ 114 more |
|
v0.32.6
patch
1 CVE
CVE-2026-50285
GHSA-ggw3-5987-rx77
Jul 15, 2026
Pomerium Pre-Auth Memory Exhaustion via Unbounded zstd Decompression in HPKE Callback
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryThe HPKE V2 URL decode path in SeverityHigh (CVSS 3.1: 7.5)
Affected Component
CWE
DescriptionUnbounded zstd Decompression in
|
v0.32.6
patch
Dependencies (122)
+ 114 more |
|
v0.32.5
patch
|
v0.32.5
patch
Dependencies (122)
+ 114 more |
|
v0.32.5-rc.1
pre
|
v0.32.5-rc.1
pre
Dependencies (132)
+ 124 more |
|
v0.32.4
patch
|
v0.32.4
patch
Dependencies (122)
+ 114 more |
|
v0.32.3
patch
|
v0.32.3
patch
Dependencies (122)
+ 114 more |
|
v0.32.2
patch
|
v0.32.2
patch
Dependencies (121)
+ 113 more |
|
v0.32.1
patch
|
v0.32.1
patch
Dependencies (121)
+ 113 more |
|
v0.32.0
minor
|
v0.32.0
minor
Dependencies (121)
+ 113 more |
|
v0.31.3
patch
|
v0.31.3
patch
Dependencies (114)
+ 106 more |
|
v0.30.8
patch
|
v0.30.8
patch
Dependencies (108)
+ 100 more |
|
v0.31.2
patch
|
v0.31.2
patch
Dependencies (114)
+ 106 more |
|
v0.31.1
patch
|
v0.31.1
patch
Dependencies (114)
+ 106 more |
|
v0.30.7
patch
|
v0.30.7
patch
Dependencies (108)
+ 100 more |
|
v0.31.0
minor
|
v0.31.0
minor
Dependencies (114)
+ 106 more |
|
v0.30.6
patch
|
v0.30.6
patch
Dependencies (108)
+ 100 more |
|
v0.30.5
patch
|
v0.30.5
patch
Dependencies (108)
+ 100 more |
|
v0.30.4
patch
|
v0.30.4
patch
Dependencies (108)
+ 100 more |
|
v0.30.2
patch
|
v0.30.2
patch
Dependencies (108)
+ 100 more |
|
v0.29.5
patch
|
v0.29.5
patch
Dependencies (96)
+ 88 more |
|
v0.30.1
patch
|
v0.30.1
patch
Dependencies (108)
+ 100 more |
|
v0.30.0
minor
|
v0.30.0
minor
Dependencies (108)
+ 100 more |
|
v0.29.1
patch
|
v0.29.1
patch
Dependencies (95)
+ 87 more |
|
v0.29.0
minor
|
v0.29.0
minor
Dependencies (95)
+ 87 more |
|
v0.28.0
minor
|
v0.28.0
minor
Dependencies (89)
+ 81 more |
|
v0.25.2
minor
2 CVEs
CVE-2024-47616
GO-2024-3179
GHSA-r7rh-jww5-5fjr
Oct 09, 2024
Pomerium service account access token may grant unintended access to databroker API in github.com/pomerium/pomerium Pomerium service account access token may grant unintended access to databroker API in github.com/pomerium/pomerium Fixed in
0.27.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-39315
GHSA-rrqr-7w59-637v
GO-2024-2965
Jul 05, 2024
Pomerium exposed OAuth2 access and ID tokens in user info endpoint response
Medium
Network
Low
Low
ImpactThe Pomerium user info page (at This issue may be more severe in the presence of an XSS vulnerability in an upstream application proxied through Pomerium. If an attacker could insert a malicious script onto a web page proxied through Pomerium, that script could access these tokens by making a request to the Upstream applications that authenticate only the ID token may be vulnerable to user impersonation using a token obtained in this manner. Note that an OAuth2 access token or ID token by itself is not sufficient to hijack a user's Pomerium session. Upstream applications should not be vulnerable to user impersonation via these tokens provided:
PatchesPatched in Pomerium v0.26.1. WorkaroundsNone For more informationIf you have any questions or comments about this advisory:
Credit to Vadim Sheydaev, aka Enr1g for reporting this issue. Fixed in
0.26.1
References Updated Sep 10, 2026 · Source: OSV.dev |
v0.25.2
minor
Dependencies (81)
+ 73 more |
|
v0.22.3
patch
2 CVEs
CVE-2024-47616
GO-2024-3179
GHSA-r7rh-jww5-5fjr
Oct 09, 2024
Pomerium service account access token may grant unintended access to databroker API in github.com/pomerium/pomerium Pomerium service account access token may grant unintended access to databroker API in github.com/pomerium/pomerium Fixed in
0.27.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-39315
GHSA-rrqr-7w59-637v
GO-2024-2965
Jul 05, 2024
Pomerium exposed OAuth2 access and ID tokens in user info endpoint response
Medium
Network
Low
Low
ImpactThe Pomerium user info page (at This issue may be more severe in the presence of an XSS vulnerability in an upstream application proxied through Pomerium. If an attacker could insert a malicious script onto a web page proxied through Pomerium, that script could access these tokens by making a request to the Upstream applications that authenticate only the ID token may be vulnerable to user impersonation using a token obtained in this manner. Note that an OAuth2 access token or ID token by itself is not sufficient to hijack a user's Pomerium session. Upstream applications should not be vulnerable to user impersonation via these tokens provided:
PatchesPatched in Pomerium v0.26.1. WorkaroundsNone For more informationIf you have any questions or comments about this advisory:
Credit to Vadim Sheydaev, aka Enr1g for reporting this issue. Fixed in
0.26.1
References Updated Sep 10, 2026 · Source: OSV.dev |
v0.22.3
patch
Dependencies (74)
+ 66 more |
|
v0.22.2
minor
2 CVEs
CVE-2024-47616
GO-2024-3179
GHSA-r7rh-jww5-5fjr
Oct 09, 2024
Pomerium service account access token may grant unintended access to databroker API in github.com/pomerium/pomerium Pomerium service account access token may grant unintended access to databroker API in github.com/pomerium/pomerium Fixed in
0.27.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-39315
GHSA-rrqr-7w59-637v
GO-2024-2965
Jul 05, 2024
Pomerium exposed OAuth2 access and ID tokens in user info endpoint response
Medium
Network
Low
Low
ImpactThe Pomerium user info page (at This issue may be more severe in the presence of an XSS vulnerability in an upstream application proxied through Pomerium. If an attacker could insert a malicious script onto a web page proxied through Pomerium, that script could access these tokens by making a request to the Upstream applications that authenticate only the ID token may be vulnerable to user impersonation using a token obtained in this manner. Note that an OAuth2 access token or ID token by itself is not sufficient to hijack a user's Pomerium session. Upstream applications should not be vulnerable to user impersonation via these tokens provided:
PatchesPatched in Pomerium v0.26.1. WorkaroundsNone For more informationIf you have any questions or comments about this advisory:
Credit to Vadim Sheydaev, aka Enr1g for reporting this issue. Fixed in
0.26.1
References Updated Sep 10, 2026 · Source: OSV.dev |
v0.22.2
minor
Dependencies (74)
+ 66 more |
|
v0.19.2
minor
2 CVEs
CVE-2024-47616
GO-2024-3179
GHSA-r7rh-jww5-5fjr
Oct 09, 2024
Pomerium service account access token may grant unintended access to databroker API in github.com/pomerium/pomerium Pomerium service account access token may grant unintended access to databroker API in github.com/pomerium/pomerium Fixed in
0.27.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-39315
GHSA-rrqr-7w59-637v
GO-2024-2965
Jul 05, 2024
Pomerium exposed OAuth2 access and ID tokens in user info endpoint response
Medium
Network
Low
Low
ImpactThe Pomerium user info page (at This issue may be more severe in the presence of an XSS vulnerability in an upstream application proxied through Pomerium. If an attacker could insert a malicious script onto a web page proxied through Pomerium, that script could access these tokens by making a request to the Upstream applications that authenticate only the ID token may be vulnerable to user impersonation using a token obtained in this manner. Note that an OAuth2 access token or ID token by itself is not sufficient to hijack a user's Pomerium session. Upstream applications should not be vulnerable to user impersonation via these tokens provided:
PatchesPatched in Pomerium v0.26.1. WorkaroundsNone For more informationIf you have any questions or comments about this advisory:
Credit to Vadim Sheydaev, aka Enr1g for reporting this issue. Fixed in
0.26.1
References Updated Sep 10, 2026 · Source: OSV.dev |
v0.19.2
minor
Dependencies (73)
+ 65 more |
|
v0.21.0-rc2
pre
2 CVEs
CVE-2024-47616
GO-2024-3179
GHSA-r7rh-jww5-5fjr
Oct 09, 2024
Pomerium service account access token may grant unintended access to databroker API in github.com/pomerium/pomerium Pomerium service account access token may grant unintended access to databroker API in github.com/pomerium/pomerium Fixed in
0.27.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-39315
GHSA-rrqr-7w59-637v
GO-2024-2965
Jul 05, 2024
Pomerium exposed OAuth2 access and ID tokens in user info endpoint response
Medium
Network
Low
Low
ImpactThe Pomerium user info page (at This issue may be more severe in the presence of an XSS vulnerability in an upstream application proxied through Pomerium. If an attacker could insert a malicious script onto a web page proxied through Pomerium, that script could access these tokens by making a request to the Upstream applications that authenticate only the ID token may be vulnerable to user impersonation using a token obtained in this manner. Note that an OAuth2 access token or ID token by itself is not sufficient to hijack a user's Pomerium session. Upstream applications should not be vulnerable to user impersonation via these tokens provided:
PatchesPatched in Pomerium v0.26.1. WorkaroundsNone For more informationIf you have any questions or comments about this advisory:
Credit to Vadim Sheydaev, aka Enr1g for reporting this issue. Fixed in
0.26.1
References Updated Sep 10, 2026 · Source: OSV.dev |
v0.21.0-rc2
pre
Dependencies (75)
+ 67 more |
|
v0.17.2
patch
3 CVEs
CVE-2024-47616
GO-2024-3179
GHSA-r7rh-jww5-5fjr
Oct 09, 2024
Pomerium service account access token may grant unintended access to databroker API in github.com/pomerium/pomerium Pomerium service account access token may grant unintended access to databroker API in github.com/pomerium/pomerium Fixed in
0.27.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-33189
GO-2023-1800
GHSA-pvrc-wvj2-f59p
Aug 20, 2024
Pomerium vulnerable to Incorrect Authorization with specially crafted requests in github.com/pomerium/pomerium Pomerium vulnerable to Incorrect Authorization with specially crafted requests in github.com/pomerium/pomerium Fixed in
0.17.4
0.18.1
0.19.2
0.20.1
0.21.4
0.22.2
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-39315
GHSA-rrqr-7w59-637v
GO-2024-2965
Jul 05, 2024
Pomerium exposed OAuth2 access and ID tokens in user info endpoint response
Medium
Network
Low
Low
ImpactThe Pomerium user info page (at This issue may be more severe in the presence of an XSS vulnerability in an upstream application proxied through Pomerium. If an attacker could insert a malicious script onto a web page proxied through Pomerium, that script could access these tokens by making a request to the Upstream applications that authenticate only the ID token may be vulnerable to user impersonation using a token obtained in this manner. Note that an OAuth2 access token or ID token by itself is not sufficient to hijack a user's Pomerium session. Upstream applications should not be vulnerable to user impersonation via these tokens provided:
PatchesPatched in Pomerium v0.26.1. WorkaroundsNone For more informationIf you have any questions or comments about this advisory:
Credit to Vadim Sheydaev, aka Enr1g for reporting this issue. Fixed in
0.26.1
References Updated Sep 10, 2026 · Source: OSV.dev |
v0.17.2
patch
Dependencies (69)
+ 61 more |
|
v0.17.0
minor
4 CVEs
CVE-2024-47616
GO-2024-3179
GHSA-r7rh-jww5-5fjr
Oct 09, 2024
Pomerium service account access token may grant unintended access to databroker API in github.com/pomerium/pomerium Pomerium service account access token may grant unintended access to databroker API in github.com/pomerium/pomerium Fixed in
0.27.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24797
GHSA-q98f-2x4p-prjr
GO-2022-0413
Sep 06, 2024
Exposure of debug and metrics endpoints in Pomerium
Medium
Network
Low
None
None
ImpactIn distributed service mode, Pomerium's Authenticate service exposes pprof debug and prometheus metrics handlers to untrusted traffic. This can leak potentially sensitive environmental information or lead to limited denial of service conditions. Patchesv0.17.1 WorkaroundsBlock access to Referenceshttps://github.com/pomerium/pomerium/pull/3212 For more informationIf you have any questions or comments about this advisory:
Fixed in
0.17.1
References
Updated Sep 06, 2024 · Source: OSV.dev
CVE-2023-33189
GO-2023-1800
GHSA-pvrc-wvj2-f59p
Aug 20, 2024
Pomerium vulnerable to Incorrect Authorization with specially crafted requests in github.com/pomerium/pomerium Pomerium vulnerable to Incorrect Authorization with specially crafted requests in github.com/pomerium/pomerium Fixed in
0.17.4
0.18.1
0.19.2
0.20.1
0.21.4
0.22.2
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-39315
GHSA-rrqr-7w59-637v
GO-2024-2965
Jul 05, 2024
Pomerium exposed OAuth2 access and ID tokens in user info endpoint response
Medium
Network
Low
Low
ImpactThe Pomerium user info page (at This issue may be more severe in the presence of an XSS vulnerability in an upstream application proxied through Pomerium. If an attacker could insert a malicious script onto a web page proxied through Pomerium, that script could access these tokens by making a request to the Upstream applications that authenticate only the ID token may be vulnerable to user impersonation using a token obtained in this manner. Note that an OAuth2 access token or ID token by itself is not sufficient to hijack a user's Pomerium session. Upstream applications should not be vulnerable to user impersonation via these tokens provided:
PatchesPatched in Pomerium v0.26.1. WorkaroundsNone For more informationIf you have any questions or comments about this advisory:
Credit to Vadim Sheydaev, aka Enr1g for reporting this issue. Fixed in
0.26.1
References Updated Sep 10, 2026 · Source: OSV.dev |
v0.17.0
minor
Dependencies (69)
+ 61 more |
|
v0.16.2
patch
5 CVEs
CVE-2024-47616
GO-2024-3179
GHSA-r7rh-jww5-5fjr
Oct 09, 2024
Pomerium service account access token may grant unintended access to databroker API in github.com/pomerium/pomerium Pomerium service account access token may grant unintended access to databroker API in github.com/pomerium/pomerium Fixed in
0.27.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24797
GHSA-q98f-2x4p-prjr
GO-2022-0413
Sep 06, 2024
Exposure of debug and metrics endpoints in Pomerium
Medium
Network
Low
None
None
ImpactIn distributed service mode, Pomerium's Authenticate service exposes pprof debug and prometheus metrics handlers to untrusted traffic. This can leak potentially sensitive environmental information or lead to limited denial of service conditions. Patchesv0.17.1 WorkaroundsBlock access to Referenceshttps://github.com/pomerium/pomerium/pull/3212 For more informationIf you have any questions or comments about this advisory:
Fixed in
0.17.1
References
Updated Sep 06, 2024 · Source: OSV.dev
CVE-2023-33189
GO-2023-1800
GHSA-pvrc-wvj2-f59p
Aug 20, 2024
Pomerium vulnerable to Incorrect Authorization with specially crafted requests in github.com/pomerium/pomerium Pomerium vulnerable to Incorrect Authorization with specially crafted requests in github.com/pomerium/pomerium Fixed in
0.17.4
0.18.1
0.19.2
0.20.1
0.21.4
0.22.2
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-39315
GHSA-rrqr-7w59-637v
GO-2024-2965
Jul 05, 2024
Pomerium exposed OAuth2 access and ID tokens in user info endpoint response
Medium
Network
Low
Low
ImpactThe Pomerium user info page (at This issue may be more severe in the presence of an XSS vulnerability in an upstream application proxied through Pomerium. If an attacker could insert a malicious script onto a web page proxied through Pomerium, that script could access these tokens by making a request to the Upstream applications that authenticate only the ID token may be vulnerable to user impersonation using a token obtained in this manner. Note that an OAuth2 access token or ID token by itself is not sufficient to hijack a user's Pomerium session. Upstream applications should not be vulnerable to user impersonation via these tokens provided:
PatchesPatched in Pomerium v0.26.1. WorkaroundsNone For more informationIf you have any questions or comments about this advisory:
Credit to Vadim Sheydaev, aka Enr1g for reporting this issue. Fixed in
0.26.1
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-j34v-3552-5r7j
Mar 01, 2022
Multiple security issues in Pomerium's embedded envoy
Medium
Envoy, which Pomerium is based on, has issued multiple CVEs impacting stability and security. Though Pomerium may not be vulnerable to all of the issues, it is recommended that all users upgrade to Pomerium v0.16.4 as soon as possible to minimize risk. Impact
PatchesPatched in v0.16.4 WorkaroundsNo References
For more informationIf you have any questions or comments about this advisory: Open an issue in pomerium/pomerium Email us at security@pomerium.com Fixed in
0.16.4
References Updated Mar 01, 2022 · Source: OSV.dev |
v0.16.2
patch
Dependencies (68)
+ 60 more |
|
v0.16.1
patch
5 CVEs
CVE-2024-47616
GO-2024-3179
GHSA-r7rh-jww5-5fjr
Oct 09, 2024
Pomerium service account access token may grant unintended access to databroker API in github.com/pomerium/pomerium Pomerium service account access token may grant unintended access to databroker API in github.com/pomerium/pomerium Fixed in
0.27.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24797
GHSA-q98f-2x4p-prjr
GO-2022-0413
Sep 06, 2024
Exposure of debug and metrics endpoints in Pomerium
Medium
Network
Low
None
None
ImpactIn distributed service mode, Pomerium's Authenticate service exposes pprof debug and prometheus metrics handlers to untrusted traffic. This can leak potentially sensitive environmental information or lead to limited denial of service conditions. Patchesv0.17.1 WorkaroundsBlock access to Referenceshttps://github.com/pomerium/pomerium/pull/3212 For more informationIf you have any questions or comments about this advisory:
Fixed in
0.17.1
References
Updated Sep 06, 2024 · Source: OSV.dev
CVE-2023-33189
GO-2023-1800
GHSA-pvrc-wvj2-f59p
Aug 20, 2024
Pomerium vulnerable to Incorrect Authorization with specially crafted requests in github.com/pomerium/pomerium Pomerium vulnerable to Incorrect Authorization with specially crafted requests in github.com/pomerium/pomerium Fixed in
0.17.4
0.18.1
0.19.2
0.20.1
0.21.4
0.22.2
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-39315
GHSA-rrqr-7w59-637v
GO-2024-2965
Jul 05, 2024
Pomerium exposed OAuth2 access and ID tokens in user info endpoint response
Medium
Network
Low
Low
ImpactThe Pomerium user info page (at This issue may be more severe in the presence of an XSS vulnerability in an upstream application proxied through Pomerium. If an attacker could insert a malicious script onto a web page proxied through Pomerium, that script could access these tokens by making a request to the Upstream applications that authenticate only the ID token may be vulnerable to user impersonation using a token obtained in this manner. Note that an OAuth2 access token or ID token by itself is not sufficient to hijack a user's Pomerium session. Upstream applications should not be vulnerable to user impersonation via these tokens provided:
PatchesPatched in Pomerium v0.26.1. WorkaroundsNone For more informationIf you have any questions or comments about this advisory:
Credit to Vadim Sheydaev, aka Enr1g for reporting this issue. Fixed in
0.26.1
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-j34v-3552-5r7j
Mar 01, 2022
Multiple security issues in Pomerium's embedded envoy
Medium
Envoy, which Pomerium is based on, has issued multiple CVEs impacting stability and security. Though Pomerium may not be vulnerable to all of the issues, it is recommended that all users upgrade to Pomerium v0.16.4 as soon as possible to minimize risk. Impact
PatchesPatched in v0.16.4 WorkaroundsNo References
For more informationIf you have any questions or comments about this advisory: Open an issue in pomerium/pomerium Email us at security@pomerium.com Fixed in
0.16.4
References Updated Mar 01, 2022 · Source: OSV.dev |
v0.16.1
patch
Dependencies (68)
+ 60 more |
|
v0.16.0
minor
5 CVEs
CVE-2024-47616
GO-2024-3179
GHSA-r7rh-jww5-5fjr
Oct 09, 2024
Pomerium service account access token may grant unintended access to databroker API in github.com/pomerium/pomerium Pomerium service account access token may grant unintended access to databroker API in github.com/pomerium/pomerium Fixed in
0.27.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24797
GHSA-q98f-2x4p-prjr
GO-2022-0413
Sep 06, 2024
Exposure of debug and metrics endpoints in Pomerium
Medium
Network
Low
None
None
ImpactIn distributed service mode, Pomerium's Authenticate service exposes pprof debug and prometheus metrics handlers to untrusted traffic. This can leak potentially sensitive environmental information or lead to limited denial of service conditions. Patchesv0.17.1 WorkaroundsBlock access to Referenceshttps://github.com/pomerium/pomerium/pull/3212 For more informationIf you have any questions or comments about this advisory:
Fixed in
0.17.1
References
Updated Sep 06, 2024 · Source: OSV.dev
CVE-2023-33189
GO-2023-1800
GHSA-pvrc-wvj2-f59p
Aug 20, 2024
Pomerium vulnerable to Incorrect Authorization with specially crafted requests in github.com/pomerium/pomerium Pomerium vulnerable to Incorrect Authorization with specially crafted requests in github.com/pomerium/pomerium Fixed in
0.17.4
0.18.1
0.19.2
0.20.1
0.21.4
0.22.2
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-39315
GHSA-rrqr-7w59-637v
GO-2024-2965
Jul 05, 2024
Pomerium exposed OAuth2 access and ID tokens in user info endpoint response
Medium
Network
Low
Low
ImpactThe Pomerium user info page (at This issue may be more severe in the presence of an XSS vulnerability in an upstream application proxied through Pomerium. If an attacker could insert a malicious script onto a web page proxied through Pomerium, that script could access these tokens by making a request to the Upstream applications that authenticate only the ID token may be vulnerable to user impersonation using a token obtained in this manner. Note that an OAuth2 access token or ID token by itself is not sufficient to hijack a user's Pomerium session. Upstream applications should not be vulnerable to user impersonation via these tokens provided:
PatchesPatched in Pomerium v0.26.1. WorkaroundsNone For more informationIf you have any questions or comments about this advisory:
Credit to Vadim Sheydaev, aka Enr1g for reporting this issue. Fixed in
0.26.1
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-j34v-3552-5r7j
Mar 01, 2022
Multiple security issues in Pomerium's embedded envoy
Medium
Envoy, which Pomerium is based on, has issued multiple CVEs impacting stability and security. Though Pomerium may not be vulnerable to all of the issues, it is recommended that all users upgrade to Pomerium v0.16.4 as soon as possible to minimize risk. Impact
PatchesPatched in v0.16.4 WorkaroundsNo References
For more informationIf you have any questions or comments about this advisory: Open an issue in pomerium/pomerium Email us at security@pomerium.com Fixed in
0.16.4
References Updated Mar 01, 2022 · Source: OSV.dev |
v0.16.0
minor
Dependencies (68)
+ 60 more |
|
v0.15.8
patch
4 CVEs
CVE-2024-47616
GO-2024-3179
GHSA-r7rh-jww5-5fjr
Oct 09, 2024
Pomerium service account access token may grant unintended access to databroker API in github.com/pomerium/pomerium Pomerium service account access token may grant unintended access to databroker API in github.com/pomerium/pomerium Fixed in
0.27.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-33189
GO-2023-1800
GHSA-pvrc-wvj2-f59p
Aug 20, 2024
Pomerium vulnerable to Incorrect Authorization with specially crafted requests in github.com/pomerium/pomerium Pomerium vulnerable to Incorrect Authorization with specially crafted requests in github.com/pomerium/pomerium Fixed in
0.17.4
0.18.1
0.19.2
0.20.1
0.21.4
0.22.2
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-39315
GHSA-rrqr-7w59-637v
GO-2024-2965
Jul 05, 2024
Pomerium exposed OAuth2 access and ID tokens in user info endpoint response
Medium
Network
Low
Low
ImpactThe Pomerium user info page (at This issue may be more severe in the presence of an XSS vulnerability in an upstream application proxied through Pomerium. If an attacker could insert a malicious script onto a web page proxied through Pomerium, that script could access these tokens by making a request to the Upstream applications that authenticate only the ID token may be vulnerable to user impersonation using a token obtained in this manner. Note that an OAuth2 access token or ID token by itself is not sufficient to hijack a user's Pomerium session. Upstream applications should not be vulnerable to user impersonation via these tokens provided:
PatchesPatched in Pomerium v0.26.1. WorkaroundsNone For more informationIf you have any questions or comments about this advisory:
Credit to Vadim Sheydaev, aka Enr1g for reporting this issue. Fixed in
0.26.1
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-j34v-3552-5r7j
Mar 01, 2022
Multiple security issues in Pomerium's embedded envoy
Medium
Envoy, which Pomerium is based on, has issued multiple CVEs impacting stability and security. Though Pomerium may not be vulnerable to all of the issues, it is recommended that all users upgrade to Pomerium v0.16.4 as soon as possible to minimize risk. Impact
PatchesPatched in v0.16.4 WorkaroundsNo References
For more informationIf you have any questions or comments about this advisory: Open an issue in pomerium/pomerium Email us at security@pomerium.com Fixed in
0.16.4
References Updated Mar 01, 2022 · Source: OSV.dev |
v0.15.8
patch
Dependencies (67)
+ 59 more |
|
v0.15.6
patch
4 CVEs
CVE-2024-47616
GO-2024-3179
GHSA-r7rh-jww5-5fjr
Oct 09, 2024
Pomerium service account access token may grant unintended access to databroker API in github.com/pomerium/pomerium Pomerium service account access token may grant unintended access to databroker API in github.com/pomerium/pomerium Fixed in
0.27.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-33189
GO-2023-1800
GHSA-pvrc-wvj2-f59p
Aug 20, 2024
Pomerium vulnerable to Incorrect Authorization with specially crafted requests in github.com/pomerium/pomerium Pomerium vulnerable to Incorrect Authorization with specially crafted requests in github.com/pomerium/pomerium Fixed in
0.17.4
0.18.1
0.19.2
0.20.1
0.21.4
0.22.2
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-39315
GHSA-rrqr-7w59-637v
GO-2024-2965
Jul 05, 2024
Pomerium exposed OAuth2 access and ID tokens in user info endpoint response
Medium
Network
Low
Low
ImpactThe Pomerium user info page (at This issue may be more severe in the presence of an XSS vulnerability in an upstream application proxied through Pomerium. If an attacker could insert a malicious script onto a web page proxied through Pomerium, that script could access these tokens by making a request to the Upstream applications that authenticate only the ID token may be vulnerable to user impersonation using a token obtained in this manner. Note that an OAuth2 access token or ID token by itself is not sufficient to hijack a user's Pomerium session. Upstream applications should not be vulnerable to user impersonation via these tokens provided:
PatchesPatched in Pomerium v0.26.1. WorkaroundsNone For more informationIf you have any questions or comments about this advisory:
Credit to Vadim Sheydaev, aka Enr1g for reporting this issue. Fixed in
0.26.1
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-j34v-3552-5r7j
Mar 01, 2022
Multiple security issues in Pomerium's embedded envoy
Medium
Envoy, which Pomerium is based on, has issued multiple CVEs impacting stability and security. Though Pomerium may not be vulnerable to all of the issues, it is recommended that all users upgrade to Pomerium v0.16.4 as soon as possible to minimize risk. Impact
PatchesPatched in v0.16.4 WorkaroundsNo References
For more informationIf you have any questions or comments about this advisory: Open an issue in pomerium/pomerium Email us at security@pomerium.com Fixed in
0.16.4
References Updated Mar 01, 2022 · Source: OSV.dev |
v0.15.6
patch
Dependencies (70)
+ 62 more |
|
v0.15.3
patch
5 CVEs
CVE-2024-47616
GO-2024-3179
GHSA-r7rh-jww5-5fjr
Oct 09, 2024
Pomerium service account access token may grant unintended access to databroker API in github.com/pomerium/pomerium Pomerium service account access token may grant unintended access to databroker API in github.com/pomerium/pomerium Fixed in
0.27.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-33189
GO-2023-1800
GHSA-pvrc-wvj2-f59p
Aug 20, 2024
Pomerium vulnerable to Incorrect Authorization with specially crafted requests in github.com/pomerium/pomerium Pomerium vulnerable to Incorrect Authorization with specially crafted requests in github.com/pomerium/pomerium Fixed in
0.17.4
0.18.1
0.19.2
0.20.1
0.21.4
0.22.2
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-39315
GHSA-rrqr-7w59-637v
GO-2024-2965
Jul 05, 2024
Pomerium exposed OAuth2 access and ID tokens in user info endpoint response
Medium
Network
Low
Low
ImpactThe Pomerium user info page (at This issue may be more severe in the presence of an XSS vulnerability in an upstream application proxied through Pomerium. If an attacker could insert a malicious script onto a web page proxied through Pomerium, that script could access these tokens by making a request to the Upstream applications that authenticate only the ID token may be vulnerable to user impersonation using a token obtained in this manner. Note that an OAuth2 access token or ID token by itself is not sufficient to hijack a user's Pomerium session. Upstream applications should not be vulnerable to user impersonation via these tokens provided:
PatchesPatched in Pomerium v0.26.1. WorkaroundsNone For more informationIf you have any questions or comments about this advisory:
Credit to Vadim Sheydaev, aka Enr1g for reporting this issue. Fixed in
0.26.1
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-j34v-3552-5r7j
Mar 01, 2022
Multiple security issues in Pomerium's embedded envoy
Medium
Envoy, which Pomerium is based on, has issued multiple CVEs impacting stability and security. Though Pomerium may not be vulnerable to all of the issues, it is recommended that all users upgrade to Pomerium v0.16.4 as soon as possible to minimize risk. Impact
PatchesPatched in v0.16.4 WorkaroundsNo References
For more informationIf you have any questions or comments about this advisory: Open an issue in pomerium/pomerium Email us at security@pomerium.com Fixed in
0.16.4
References Updated Mar 01, 2022 · Source: OSV.dev
CVE-2021-41230
GO-2021-0258
GHSA-j6wp-3859-vxfg
Jan 14, 2022
Incorrect authorization in github.com/pomerium/pomerium Pomerium is an open source identity-aware access proxy. Changes to the OIDC claims of a user after initial login are not reflected in policy evaluation when using allowed_idp_claims as part of policy. If using allowed_idp_claims and a user's claims are changed, Pomerium can make incorrect authorization decisions. For users unable to upgrade clear data on databroker service by clearing redis or restarting the in-memory databroker to force claims to be updated. Fixed in
0.15.6
References Updated May 20, 2024 · Source: OSV.dev |
v0.15.3
patch
Dependencies (67)
+ 59 more |
|
v0.15.1
minor
5 CVEs
CVE-2024-47616
GO-2024-3179
GHSA-r7rh-jww5-5fjr
Oct 09, 2024
Pomerium service account access token may grant unintended access to databroker API in github.com/pomerium/pomerium Pomerium service account access token may grant unintended access to databroker API in github.com/pomerium/pomerium Fixed in
0.27.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-33189
GO-2023-1800
GHSA-pvrc-wvj2-f59p
Aug 20, 2024
Pomerium vulnerable to Incorrect Authorization with specially crafted requests in github.com/pomerium/pomerium Pomerium vulnerable to Incorrect Authorization with specially crafted requests in github.com/pomerium/pomerium Fixed in
0.17.4
0.18.1
0.19.2
0.20.1
0.21.4
0.22.2
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-39315
GHSA-rrqr-7w59-637v
GO-2024-2965
Jul 05, 2024
Pomerium exposed OAuth2 access and ID tokens in user info endpoint response
Medium
Network
Low
Low
ImpactThe Pomerium user info page (at This issue may be more severe in the presence of an XSS vulnerability in an upstream application proxied through Pomerium. If an attacker could insert a malicious script onto a web page proxied through Pomerium, that script could access these tokens by making a request to the Upstream applications that authenticate only the ID token may be vulnerable to user impersonation using a token obtained in this manner. Note that an OAuth2 access token or ID token by itself is not sufficient to hijack a user's Pomerium session. Upstream applications should not be vulnerable to user impersonation via these tokens provided:
PatchesPatched in Pomerium v0.26.1. WorkaroundsNone For more informationIf you have any questions or comments about this advisory:
Credit to Vadim Sheydaev, aka Enr1g for reporting this issue. Fixed in
0.26.1
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-j34v-3552-5r7j
Mar 01, 2022
Multiple security issues in Pomerium's embedded envoy
Medium
Envoy, which Pomerium is based on, has issued multiple CVEs impacting stability and security. Though Pomerium may not be vulnerable to all of the issues, it is recommended that all users upgrade to Pomerium v0.16.4 as soon as possible to minimize risk. Impact
PatchesPatched in v0.16.4 WorkaroundsNo References
For more informationIf you have any questions or comments about this advisory: Open an issue in pomerium/pomerium Email us at security@pomerium.com Fixed in
0.16.4
References Updated Mar 01, 2022 · Source: OSV.dev
CVE-2021-41230
GO-2021-0258
GHSA-j6wp-3859-vxfg
Jan 14, 2022
Incorrect authorization in github.com/pomerium/pomerium Pomerium is an open source identity-aware access proxy. Changes to the OIDC claims of a user after initial login are not reflected in policy evaluation when using allowed_idp_claims as part of policy. If using allowed_idp_claims and a user's claims are changed, Pomerium can make incorrect authorization decisions. For users unable to upgrade clear data on databroker service by clearing redis or restarting the in-memory databroker to force claims to be updated. Fixed in
0.15.6
References Updated May 20, 2024 · Source: OSV.dev |
v0.15.1
minor
Dependencies (66)
+ 58 more |
|
v0.14.5
patch
8 CVEs
CVE-2024-47616
GO-2024-3179
GHSA-r7rh-jww5-5fjr
Oct 09, 2024
Pomerium service account access token may grant unintended access to databroker API in github.com/pomerium/pomerium Pomerium service account access token may grant unintended access to databroker API in github.com/pomerium/pomerium Fixed in
0.27.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-39162
GO-2022-0933
BIT-envoy-2021-39162
GHSA-gjcg-vrxg-xmgv
Aug 21, 2024
Incorrect handling of H2 GOAWAY + SETTINGS frames in github.com/pomerium/pomerium Incorrect handling of H2 GOAWAY + SETTINGS frames in github.com/pomerium/pomerium Fixed in
0.15.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-33189
GO-2023-1800
GHSA-pvrc-wvj2-f59p
Aug 20, 2024
Pomerium vulnerable to Incorrect Authorization with specially crafted requests in github.com/pomerium/pomerium Pomerium vulnerable to Incorrect Authorization with specially crafted requests in github.com/pomerium/pomerium Fixed in
0.17.4
0.18.1
0.19.2
0.20.1
0.21.4
0.22.2
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-39315
GHSA-rrqr-7w59-637v
GO-2024-2965
Jul 05, 2024
Pomerium exposed OAuth2 access and ID tokens in user info endpoint response
Medium
Network
Low
Low
ImpactThe Pomerium user info page (at This issue may be more severe in the presence of an XSS vulnerability in an upstream application proxied through Pomerium. If an attacker could insert a malicious script onto a web page proxied through Pomerium, that script could access these tokens by making a request to the Upstream applications that authenticate only the ID token may be vulnerable to user impersonation using a token obtained in this manner. Note that an OAuth2 access token or ID token by itself is not sufficient to hijack a user's Pomerium session. Upstream applications should not be vulnerable to user impersonation via these tokens provided:
PatchesPatched in Pomerium v0.26.1. WorkaroundsNone For more informationIf you have any questions or comments about this advisory:
Credit to Vadim Sheydaev, aka Enr1g for reporting this issue. Fixed in
0.26.1
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-j34v-3552-5r7j
Mar 01, 2022
Multiple security issues in Pomerium's embedded envoy
Medium
Envoy, which Pomerium is based on, has issued multiple CVEs impacting stability and security. Though Pomerium may not be vulnerable to all of the issues, it is recommended that all users upgrade to Pomerium v0.16.4 as soon as possible to minimize risk. Impact
PatchesPatched in v0.16.4 WorkaroundsNo References
For more informationIf you have any questions or comments about this advisory: Open an issue in pomerium/pomerium Email us at security@pomerium.com Fixed in
0.16.4
References Updated Mar 01, 2022 · Source: OSV.dev
CVE-2021-41230
GO-2021-0258
GHSA-j6wp-3859-vxfg
Jan 14, 2022
Incorrect authorization in github.com/pomerium/pomerium Pomerium is an open source identity-aware access proxy. Changes to the OIDC claims of a user after initial login are not reflected in policy evaluation when using allowed_idp_claims as part of policy. If using allowed_idp_claims and a user's claims are changed, Pomerium can make incorrect authorization decisions. For users unable to upgrade clear data on databroker service by clearing redis or restarting the in-memory databroker to force claims to be updated. Fixed in
0.15.6
References Updated May 20, 2024 · Source: OSV.dev
CVE-2021-39206
GHSA-cfc2-wjcm-c8fm
BIT-envoy-2021-39206
Sep 10, 2021
Incorrect Authorization with specially crafted requests
8.6
/ 10
High
Network
Low
None
None
Changed
High
None
None
Envoy, which Pomerium is based on, contains two authorization related vulnerabilities:
ImpactWith specially crafted requests, incorrect authorization or routing decisions may be made by Pomerium. PatchesPomerium v0.14.8 and v0.15.1 contain an upgraded envoy binary with these vulnerabilities patched. Workarounds
Referencesenvoy GSA CVE-2021-32777 envoy GSA CVE-2021-32779 envoy announcement For more informationIf you have any questions or comments about this advisory:
Affected versions
0.15.0
Fixed in
0.14.8
0.15.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-39204
GHSA-5wjf-62hw-q78r
BIT-envoy-2021-39204
Sep 10, 2021
Excessive CPU usage
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Envoy, which Pomerium is based on, incorrectly handles resetting of HTTP/2 streams with excessive complexity. This can lead to high CPU utilization when a large number of streams are reset. ImpactThis can result in a DoS condition. PatchesPomerium versions 0.14.8 and 0.15.1 contain an upgraded envoy binary with this vulnerability patched. WorkaroundsN/A Referencesenvoy GSA envoy CVE envoy announcement For more informationIf you have any questions or comments about this advisory:
Affected versions
0.15.0
Fixed in
0.14.8
0.15.1
References
Updated Feb 04, 2026 · Source: OSV.dev |
v0.14.5
patch
Dependencies (63)
+ 55 more |
|
v0.14.3
minor
8 CVEs
CVE-2024-47616
GO-2024-3179
GHSA-r7rh-jww5-5fjr
Oct 09, 2024
Pomerium service account access token may grant unintended access to databroker API in github.com/pomerium/pomerium Pomerium service account access token may grant unintended access to databroker API in github.com/pomerium/pomerium Fixed in
0.27.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-39162
GO-2022-0933
BIT-envoy-2021-39162
GHSA-gjcg-vrxg-xmgv
Aug 21, 2024
Incorrect handling of H2 GOAWAY + SETTINGS frames in github.com/pomerium/pomerium Incorrect handling of H2 GOAWAY + SETTINGS frames in github.com/pomerium/pomerium Fixed in
0.15.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-33189
GO-2023-1800
GHSA-pvrc-wvj2-f59p
Aug 20, 2024
Pomerium vulnerable to Incorrect Authorization with specially crafted requests in github.com/pomerium/pomerium Pomerium vulnerable to Incorrect Authorization with specially crafted requests in github.com/pomerium/pomerium Fixed in
0.17.4
0.18.1
0.19.2
0.20.1
0.21.4
0.22.2
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-39315
GHSA-rrqr-7w59-637v
GO-2024-2965
Jul 05, 2024
Pomerium exposed OAuth2 access and ID tokens in user info endpoint response
Medium
Network
Low
Low
ImpactThe Pomerium user info page (at This issue may be more severe in the presence of an XSS vulnerability in an upstream application proxied through Pomerium. If an attacker could insert a malicious script onto a web page proxied through Pomerium, that script could access these tokens by making a request to the Upstream applications that authenticate only the ID token may be vulnerable to user impersonation using a token obtained in this manner. Note that an OAuth2 access token or ID token by itself is not sufficient to hijack a user's Pomerium session. Upstream applications should not be vulnerable to user impersonation via these tokens provided:
PatchesPatched in Pomerium v0.26.1. WorkaroundsNone For more informationIf you have any questions or comments about this advisory:
Credit to Vadim Sheydaev, aka Enr1g for reporting this issue. Fixed in
0.26.1
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-j34v-3552-5r7j
Mar 01, 2022
Multiple security issues in Pomerium's embedded envoy
Medium
Envoy, which Pomerium is based on, has issued multiple CVEs impacting stability and security. Though Pomerium may not be vulnerable to all of the issues, it is recommended that all users upgrade to Pomerium v0.16.4 as soon as possible to minimize risk. Impact
PatchesPatched in v0.16.4 WorkaroundsNo References
For more informationIf you have any questions or comments about this advisory: Open an issue in pomerium/pomerium Email us at security@pomerium.com Fixed in
0.16.4
References Updated Mar 01, 2022 · Source: OSV.dev
CVE-2021-41230
GO-2021-0258
GHSA-j6wp-3859-vxfg
Jan 14, 2022
Incorrect authorization in github.com/pomerium/pomerium Pomerium is an open source identity-aware access proxy. Changes to the OIDC claims of a user after initial login are not reflected in policy evaluation when using allowed_idp_claims as part of policy. If using allowed_idp_claims and a user's claims are changed, Pomerium can make incorrect authorization decisions. For users unable to upgrade clear data on databroker service by clearing redis or restarting the in-memory databroker to force claims to be updated. Fixed in
0.15.6
References Updated May 20, 2024 · Source: OSV.dev
CVE-2021-39206
GHSA-cfc2-wjcm-c8fm
BIT-envoy-2021-39206
Sep 10, 2021
Incorrect Authorization with specially crafted requests
8.6
/ 10
High
Network
Low
None
None
Changed
High
None
None
Envoy, which Pomerium is based on, contains two authorization related vulnerabilities:
ImpactWith specially crafted requests, incorrect authorization or routing decisions may be made by Pomerium. PatchesPomerium v0.14.8 and v0.15.1 contain an upgraded envoy binary with these vulnerabilities patched. Workarounds
Referencesenvoy GSA CVE-2021-32777 envoy GSA CVE-2021-32779 envoy announcement For more informationIf you have any questions or comments about this advisory:
Affected versions
0.15.0
Fixed in
0.14.8
0.15.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-39204
GHSA-5wjf-62hw-q78r
BIT-envoy-2021-39204
Sep 10, 2021
Excessive CPU usage
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Envoy, which Pomerium is based on, incorrectly handles resetting of HTTP/2 streams with excessive complexity. This can lead to high CPU utilization when a large number of streams are reset. ImpactThis can result in a DoS condition. PatchesPomerium versions 0.14.8 and 0.15.1 contain an upgraded envoy binary with this vulnerability patched. WorkaroundsN/A Referencesenvoy GSA envoy CVE envoy announcement For more informationIf you have any questions or comments about this advisory:
Affected versions
0.15.0
Fixed in
0.14.8
0.15.1
References
Updated Feb 04, 2026 · Source: OSV.dev |
v0.14.3
minor
Dependencies (63)
+ 55 more |
|
v0.14.0-rc2
pre
8 CVEs
CVE-2024-47616
GO-2024-3179
GHSA-r7rh-jww5-5fjr
Oct 09, 2024
Pomerium service account access token may grant unintended access to databroker API in github.com/pomerium/pomerium Pomerium service account access token may grant unintended access to databroker API in github.com/pomerium/pomerium Fixed in
0.27.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-39162
GO-2022-0933
BIT-envoy-2021-39162
GHSA-gjcg-vrxg-xmgv
Aug 21, 2024
Incorrect handling of H2 GOAWAY + SETTINGS frames in github.com/pomerium/pomerium Incorrect handling of H2 GOAWAY + SETTINGS frames in github.com/pomerium/pomerium Fixed in
0.15.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-33189
GO-2023-1800
GHSA-pvrc-wvj2-f59p
Aug 20, 2024
Pomerium vulnerable to Incorrect Authorization with specially crafted requests in github.com/pomerium/pomerium Pomerium vulnerable to Incorrect Authorization with specially crafted requests in github.com/pomerium/pomerium Fixed in
0.17.4
0.18.1
0.19.2
0.20.1
0.21.4
0.22.2
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-39315
GHSA-rrqr-7w59-637v
GO-2024-2965
Jul 05, 2024
Pomerium exposed OAuth2 access and ID tokens in user info endpoint response
Medium
Network
Low
Low
ImpactThe Pomerium user info page (at This issue may be more severe in the presence of an XSS vulnerability in an upstream application proxied through Pomerium. If an attacker could insert a malicious script onto a web page proxied through Pomerium, that script could access these tokens by making a request to the Upstream applications that authenticate only the ID token may be vulnerable to user impersonation using a token obtained in this manner. Note that an OAuth2 access token or ID token by itself is not sufficient to hijack a user's Pomerium session. Upstream applications should not be vulnerable to user impersonation via these tokens provided:
PatchesPatched in Pomerium v0.26.1. WorkaroundsNone For more informationIf you have any questions or comments about this advisory:
Credit to Vadim Sheydaev, aka Enr1g for reporting this issue. Fixed in
0.26.1
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-j34v-3552-5r7j
Mar 01, 2022
Multiple security issues in Pomerium's embedded envoy
Medium
Envoy, which Pomerium is based on, has issued multiple CVEs impacting stability and security. Though Pomerium may not be vulnerable to all of the issues, it is recommended that all users upgrade to Pomerium v0.16.4 as soon as possible to minimize risk. Impact
PatchesPatched in v0.16.4 WorkaroundsNo References
For more informationIf you have any questions or comments about this advisory: Open an issue in pomerium/pomerium Email us at security@pomerium.com Fixed in
0.16.4
References Updated Mar 01, 2022 · Source: OSV.dev
CVE-2021-41230
GO-2021-0258
GHSA-j6wp-3859-vxfg
Jan 14, 2022
Incorrect authorization in github.com/pomerium/pomerium Pomerium is an open source identity-aware access proxy. Changes to the OIDC claims of a user after initial login are not reflected in policy evaluation when using allowed_idp_claims as part of policy. If using allowed_idp_claims and a user's claims are changed, Pomerium can make incorrect authorization decisions. For users unable to upgrade clear data on databroker service by clearing redis or restarting the in-memory databroker to force claims to be updated. Fixed in
0.15.6
References Updated May 20, 2024 · Source: OSV.dev
CVE-2021-39206
GHSA-cfc2-wjcm-c8fm
BIT-envoy-2021-39206
Sep 10, 2021
Incorrect Authorization with specially crafted requests
8.6
/ 10
High
Network
Low
None
None
Changed
High
None
None
Envoy, which Pomerium is based on, contains two authorization related vulnerabilities:
ImpactWith specially crafted requests, incorrect authorization or routing decisions may be made by Pomerium. PatchesPomerium v0.14.8 and v0.15.1 contain an upgraded envoy binary with these vulnerabilities patched. Workarounds
Referencesenvoy GSA CVE-2021-32777 envoy GSA CVE-2021-32779 envoy announcement For more informationIf you have any questions or comments about this advisory:
Affected versions
0.15.0
Fixed in
0.14.8
0.15.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-39204
GHSA-5wjf-62hw-q78r
BIT-envoy-2021-39204
Sep 10, 2021
Excessive CPU usage
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Envoy, which Pomerium is based on, incorrectly handles resetting of HTTP/2 streams with excessive complexity. This can lead to high CPU utilization when a large number of streams are reset. ImpactThis can result in a DoS condition. PatchesPomerium versions 0.14.8 and 0.15.1 contain an upgraded envoy binary with this vulnerability patched. WorkaroundsN/A Referencesenvoy GSA envoy CVE envoy announcement For more informationIf you have any questions or comments about this advisory:
Affected versions
0.15.0
Fixed in
0.14.8
0.15.1
References
Updated Feb 04, 2026 · Source: OSV.dev |
v0.14.0-rc2
pre
Dependencies (63)
+ 55 more |
|
v0.13.4
patch
8 CVEs
CVE-2024-47616
GO-2024-3179
GHSA-r7rh-jww5-5fjr
Oct 09, 2024
Pomerium service account access token may grant unintended access to databroker API in github.com/pomerium/pomerium Pomerium service account access token may grant unintended access to databroker API in github.com/pomerium/pomerium Fixed in
0.27.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-39162
GO-2022-0933
BIT-envoy-2021-39162
GHSA-gjcg-vrxg-xmgv
Aug 21, 2024
Incorrect handling of H2 GOAWAY + SETTINGS frames in github.com/pomerium/pomerium Incorrect handling of H2 GOAWAY + SETTINGS frames in github.com/pomerium/pomerium Fixed in
0.15.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-33189
GO-2023-1800
GHSA-pvrc-wvj2-f59p
Aug 20, 2024
Pomerium vulnerable to Incorrect Authorization with specially crafted requests in github.com/pomerium/pomerium Pomerium vulnerable to Incorrect Authorization with specially crafted requests in github.com/pomerium/pomerium Fixed in
0.17.4
0.18.1
0.19.2
0.20.1
0.21.4
0.22.2
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-39315
GHSA-rrqr-7w59-637v
GO-2024-2965
Jul 05, 2024
Pomerium exposed OAuth2 access and ID tokens in user info endpoint response
Medium
Network
Low
Low
ImpactThe Pomerium user info page (at This issue may be more severe in the presence of an XSS vulnerability in an upstream application proxied through Pomerium. If an attacker could insert a malicious script onto a web page proxied through Pomerium, that script could access these tokens by making a request to the Upstream applications that authenticate only the ID token may be vulnerable to user impersonation using a token obtained in this manner. Note that an OAuth2 access token or ID token by itself is not sufficient to hijack a user's Pomerium session. Upstream applications should not be vulnerable to user impersonation via these tokens provided:
PatchesPatched in Pomerium v0.26.1. WorkaroundsNone For more informationIf you have any questions or comments about this advisory:
Credit to Vadim Sheydaev, aka Enr1g for reporting this issue. Fixed in
0.26.1
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-j34v-3552-5r7j
Mar 01, 2022
Multiple security issues in Pomerium's embedded envoy
Medium
Envoy, which Pomerium is based on, has issued multiple CVEs impacting stability and security. Though Pomerium may not be vulnerable to all of the issues, it is recommended that all users upgrade to Pomerium v0.16.4 as soon as possible to minimize risk. Impact
PatchesPatched in v0.16.4 WorkaroundsNo References
For more informationIf you have any questions or comments about this advisory: Open an issue in pomerium/pomerium Email us at security@pomerium.com Fixed in
0.16.4
References Updated Mar 01, 2022 · Source: OSV.dev
CVE-2021-41230
GO-2021-0258
GHSA-j6wp-3859-vxfg
Jan 14, 2022
Incorrect authorization in github.com/pomerium/pomerium Pomerium is an open source identity-aware access proxy. Changes to the OIDC claims of a user after initial login are not reflected in policy evaluation when using allowed_idp_claims as part of policy. If using allowed_idp_claims and a user's claims are changed, Pomerium can make incorrect authorization decisions. For users unable to upgrade clear data on databroker service by clearing redis or restarting the in-memory databroker to force claims to be updated. Fixed in
0.15.6
References Updated May 20, 2024 · Source: OSV.dev
CVE-2021-39206
GHSA-cfc2-wjcm-c8fm
BIT-envoy-2021-39206
Sep 10, 2021
Incorrect Authorization with specially crafted requests
8.6
/ 10
High
Network
Low
None
None
Changed
High
None
None
Envoy, which Pomerium is based on, contains two authorization related vulnerabilities:
ImpactWith specially crafted requests, incorrect authorization or routing decisions may be made by Pomerium. PatchesPomerium v0.14.8 and v0.15.1 contain an upgraded envoy binary with these vulnerabilities patched. Workarounds
Referencesenvoy GSA CVE-2021-32777 envoy GSA CVE-2021-32779 envoy announcement For more informationIf you have any questions or comments about this advisory:
Affected versions
0.15.0
Fixed in
0.14.8
0.15.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-39204
GHSA-5wjf-62hw-q78r
BIT-envoy-2021-39204
Sep 10, 2021
Excessive CPU usage
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Envoy, which Pomerium is based on, incorrectly handles resetting of HTTP/2 streams with excessive complexity. This can lead to high CPU utilization when a large number of streams are reset. ImpactThis can result in a DoS condition. PatchesPomerium versions 0.14.8 and 0.15.1 contain an upgraded envoy binary with this vulnerability patched. WorkaroundsN/A Referencesenvoy GSA envoy CVE envoy announcement For more informationIf you have any questions or comments about this advisory:
Affected versions
0.15.0
Fixed in
0.14.8
0.15.1
References
Updated Feb 04, 2026 · Source: OSV.dev |
v0.13.4
patch
Dependencies (59)
+ 51 more |
|
v0.13.3
patch
10 CVEs
CVE-2024-47616
GO-2024-3179
GHSA-r7rh-jww5-5fjr
Oct 09, 2024
Pomerium service account access token may grant unintended access to databroker API in github.com/pomerium/pomerium Pomerium service account access token may grant unintended access to databroker API in github.com/pomerium/pomerium Fixed in
0.27.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-39162
GO-2022-0933
BIT-envoy-2021-39162
GHSA-gjcg-vrxg-xmgv
Aug 21, 2024
Incorrect handling of H2 GOAWAY + SETTINGS frames in github.com/pomerium/pomerium Incorrect handling of H2 GOAWAY + SETTINGS frames in github.com/pomerium/pomerium Fixed in
0.15.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-29652
GO-2022-0827
GHSA-fv82-r8qv-ch4v
Aug 21, 2024
pomerium_signature is not verified in middleware in github.com/pomerium/pomerium pomerium_signature is not verified in middleware in github.com/pomerium/pomerium Fixed in
0.13.4
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-29651
GO-2022-0783
GHSA-35vc-w93w-75c2
Aug 21, 2024
JWT leak via Open Redirect in Programmatic access in github.com/pomerium/pomerium JWT leak via Open Redirect in Programmatic access in github.com/pomerium/pomerium Fixed in
0.13.4
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-33189
GO-2023-1800
GHSA-pvrc-wvj2-f59p
Aug 20, 2024
Pomerium vulnerable to Incorrect Authorization with specially crafted requests in github.com/pomerium/pomerium Pomerium vulnerable to Incorrect Authorization with specially crafted requests in github.com/pomerium/pomerium Fixed in
0.17.4
0.18.1
0.19.2
0.20.1
0.21.4
0.22.2
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-39315
GHSA-rrqr-7w59-637v
GO-2024-2965
Jul 05, 2024
Pomerium exposed OAuth2 access and ID tokens in user info endpoint response
Medium
Network
Low
Low
ImpactThe Pomerium user info page (at This issue may be more severe in the presence of an XSS vulnerability in an upstream application proxied through Pomerium. If an attacker could insert a malicious script onto a web page proxied through Pomerium, that script could access these tokens by making a request to the Upstream applications that authenticate only the ID token may be vulnerable to user impersonation using a token obtained in this manner. Note that an OAuth2 access token or ID token by itself is not sufficient to hijack a user's Pomerium session. Upstream applications should not be vulnerable to user impersonation via these tokens provided:
PatchesPatched in Pomerium v0.26.1. WorkaroundsNone For more informationIf you have any questions or comments about this advisory:
Credit to Vadim Sheydaev, aka Enr1g for reporting this issue. Fixed in
0.26.1
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-j34v-3552-5r7j
Mar 01, 2022
Multiple security issues in Pomerium's embedded envoy
Medium
Envoy, which Pomerium is based on, has issued multiple CVEs impacting stability and security. Though Pomerium may not be vulnerable to all of the issues, it is recommended that all users upgrade to Pomerium v0.16.4 as soon as possible to minimize risk. Impact
PatchesPatched in v0.16.4 WorkaroundsNo References
For more informationIf you have any questions or comments about this advisory: Open an issue in pomerium/pomerium Email us at security@pomerium.com Fixed in
0.16.4
References Updated Mar 01, 2022 · Source: OSV.dev
CVE-2021-41230
GO-2021-0258
GHSA-j6wp-3859-vxfg
Jan 14, 2022
Incorrect authorization in github.com/pomerium/pomerium Pomerium is an open source identity-aware access proxy. Changes to the OIDC claims of a user after initial login are not reflected in policy evaluation when using allowed_idp_claims as part of policy. If using allowed_idp_claims and a user's claims are changed, Pomerium can make incorrect authorization decisions. For users unable to upgrade clear data on databroker service by clearing redis or restarting the in-memory databroker to force claims to be updated. Fixed in
0.15.6
References Updated May 20, 2024 · Source: OSV.dev
CVE-2021-39206
GHSA-cfc2-wjcm-c8fm
BIT-envoy-2021-39206
Sep 10, 2021
Incorrect Authorization with specially crafted requests
8.6
/ 10
High
Network
Low
None
None
Changed
High
None
None
Envoy, which Pomerium is based on, contains two authorization related vulnerabilities:
ImpactWith specially crafted requests, incorrect authorization or routing decisions may be made by Pomerium. PatchesPomerium v0.14.8 and v0.15.1 contain an upgraded envoy binary with these vulnerabilities patched. Workarounds
Referencesenvoy GSA CVE-2021-32777 envoy GSA CVE-2021-32779 envoy announcement For more informationIf you have any questions or comments about this advisory:
Affected versions
0.15.0
Fixed in
0.14.8
0.15.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-39204
GHSA-5wjf-62hw-q78r
BIT-envoy-2021-39204
Sep 10, 2021
Excessive CPU usage
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Envoy, which Pomerium is based on, incorrectly handles resetting of HTTP/2 streams with excessive complexity. This can lead to high CPU utilization when a large number of streams are reset. ImpactThis can result in a DoS condition. PatchesPomerium versions 0.14.8 and 0.15.1 contain an upgraded envoy binary with this vulnerability patched. WorkaroundsN/A Referencesenvoy GSA envoy CVE envoy announcement For more informationIf you have any questions or comments about this advisory:
Affected versions
0.15.0
Fixed in
0.14.8
0.15.1
References
Updated Feb 04, 2026 · Source: OSV.dev |
v0.13.3
patch
Dependencies (59)
+ 51 more |