Goauthentik
9 known vulnerabilities
Top Products
authentik is an open-source identity provider. Prior to versions 2025.12.6, 2026.2.4, and 2026.5.1, the Source stage can
authentik is an open-source identity provider. Prior to versions 2025.12.6, 2026.2.4, and 2026.5.1, an attacker with the
authentik is an open-source identity provider. Prior to versions 2025.12.5, 2026.2.3, and 2026.5.1, authentik's SAML Sou
authentik is an open-source identity provider. Prior to versions 2025.12.5 and 2026.2.3, due to the implementation of st
authentik is an open-source identity provider. Prior to version 2026.2.3, the WS-Federation provider validates the user-
authentik is an open-source identity provider. Prior to versions 2025.12.5 and 2026.2.3, the SAML source response proces
authentik is an open-source identity provider. Prior to 2025.8.6, 2025.10.4, and 2025.12.4, when using a SAML Source tha
authentik is an open-source identity provider. Prior to 2025.10.4 and 2025.12.4, with a malformed cookie it was possible
authentik is an open-source identity provider. From 2021.3.1 to before 2025.8.6, 2025.10.4, and 2025.12.4, when using de
Frequently Asked Questions
How many CVEs affect Goauthentik?
Goauthentik has 9 CVE records in our database, including 3 critical and 5 high severity vulnerabilities.
What are the most severe Goauthentik vulnerabilities?
Goauthentik has 3 critical severity (CVSS 9.0+) and 5 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for Goauthentik vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Goauthentik products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Goauthentik Vulnerabilities
CyberStrike scans your infrastructure for Goauthentik vulnerabilities and provides real-time remediation guidance.
Get Started