CRITICAL9.8Go
GHSA-2x32-jm95-2cpx· CVE-2020-26290, CVE-2020-27847Authentication Bypass in dex
Modified: 9/10/2026
package
pkg:go/github.com/dexidp/dex
Authentication Bypass in dex
Modified: 9/10/2026
Dex: Token-exchange endpoint is missing AllowedConnectors enforcement
Modified: 6/25/2026
Dex discarding TLSconfig and always serves deprecated TLS 1.0/1.1 and insecure ciphers
Modified: 9/10/2026
Critical security issues in XML encoding in github.com/dexidp/dex
Modified: 9/10/2026
Dex vulnerable to Man-in-the-Middle allowing ID token capture via intercepted authorization code
Modified: 9/10/2026
Dex discarding TLSconfig and always serves deprecated TLS 1.0/1.1 and insecure ciphers in github.com/dexidp/dex
Modified: 2/4/2026
Dex: Token-exchange endpoint is missing AllowedConnectors enforcement in github.com/dexidp/dex
Modified: 6/25/2026