Junglewise Threat Intelligence

Authorizer: Password reset token theft and full auth token redirect via unvalidated redirect_uri

Severity: medium · CVSS 4 · Published 2026-04-06

Technologies: github.com/authorizerdev/authorizer (Go). Vendors: Go.

Executive brief

Authorizer: Password reset token theft and full auth token redirect via unvalidated redirect_uri

Affected products

  • Go github.com/authorizerdev/authorizer

Related threats