{"id":"GO-2026-5959","summary":"Authorizer: Unvalidated redirect_uri in /authorize leaks OAuth2 tokens to attacker-controlled URL in github.com/authorizerdev/authorizer","details":"Authorizer: Unvalidated redirect_uri in /authorize leaks OAuth2 tokens to attacker-controlled URL in github.com/authorizerdev/authorizer","aliases":["CVE-2026-54072","GHSA-h29v-hj44-q8cv"],"modified":"2026-07-21T19:15:27.754638332Z","published":"2026-07-17T19:42:05Z","database_specific":{"url":"https://pkg.go.dev/vuln/GO-2026-5959","review_status":"UNREVIEWED"},"references":[{"type":"ADVISORY","url":"https://github.com/authorizerdev/authorizer/security/advisories/GHSA-h29v-hj44-q8cv"}],"affected":[{"package":{"name":"github.com/authorizerdev/authorizer","ecosystem":"Go","purl":"pkg:golang/github.com/authorizerdev/authorizer"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.0.0-20260409051328-bd3f5baf6d3d"}]}],"ecosystem_specific":{},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2026-5959.json"}}],"schema_version":"1.7.5"}