📦 Workers Oauth Provider

by Cloudflare

🔍 What is Workers Oauth Provider?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-4144

CRITICAL CVSS 9.8 May 1, 2025

This vulnerability allows attackers to bypass PKCE (Proof Key for Code Exchange) protection in the workers-oauth-provider component of Cloudflare's MCP framework. Attackers could potentially intercept...

CVE-2025-4143

MEDIUM CVSS 6.1 May 1, 2025

This CVE describes an OAuth redirect URI validation vulnerability in the workers-oauth-provider library used in Cloudflare's MCP framework. Attackers can exploit this to steal user credentials and imp...