Executive brief
Authorizer: Password reset token theft and full auth token redirect via unvalidated redirect_uri
Affected products
- Go github.com/authorizerdev/authorizer
Junglewise Threat Intelligence
Severity: medium · CVSS 4 · Published 2026-04-06
Technologies: github.com/authorizerdev/authorizer (Go). Vendors: Go.
Authorizer: Password reset token theft and full auth token redirect via unvalidated redirect_uri