{"schema_version":"1.7.5","id":"GO-2026-4804","published":"2026-03-23T18:16:18Z","modified":"2026-03-23T18:45:23.126768Z","aliases":["CVE-2026-33494","GHSA-p224-6x5r-fjpm"],"summary":"Ory Oathkeeper has a path traversal authorization bypass in github.com/ory/oathkeeper","details":"Ory Oathkeeper has a path traversal authorization bypass in github.com/ory/oathkeeper","affected":[{"package":{"name":"github.com/ory/oathkeeper","ecosystem":"Go","purl":"pkg:golang/github.com/ory/oathkeeper"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.40.10-0.20260320084758-8e0002140491"}]}],"ecosystem_specific":{},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2026-4804.json"}}],"references":[{"type":"ADVISORY","url":"https://github.com/ory/oathkeeper/security/advisories/GHSA-p224-6x5r-fjpm"},{"type":"FIX","url":"https://github.com/ory/oathkeeper/commit/8e0002140491c592db41fa141dc6ad68f417e2b2"}],"database_specific":{"review_status":"UNREVIEWED","url":"https://pkg.go.dev/vuln/GO-2026-4804"}}