Vulnerability Report: GO-2026-5231
- GHSA-7qjx-gp9h-65qj
- Affects: github.com/dexidp/dex
- Published: Jun 25, 2026
- Unreviewed
Dex: Token-exchange endpoint is missing AllowedConnectors enforcement in github.com/dexidp/dex
For detailed information about this vulnerability, visit https://github.com/dexidp/dex/security/advisories/GHSA-7qjx-gp9h-65qj.
Affected Modules
-
PathGo Versions
-
before v0.0.0-20260303131938-204dbb2e3ff7
Aliases
References
- https://github.com/dexidp/dex/security/advisories/GHSA-7qjx-gp9h-65qj
- https://github.com/dexidp/dex/commit/204dbb2e3ff7692af3b7ca4362b1ee46fb43c227
- https://vuln.go.dev/ID/GO-2026-5231.json
Feedback
This report is unreviewed. It was automatically generated from a third-party source and its details have not been verified by the Go team.
See anything missing or incorrect?
Suggest an edit to this report.