Pomerium Security Vulnerabilities (CVEs)
Track 4 security vulnerabilities affecting Pomerium products and software. Get instant email alerts when new CVEs are discovered, automated security monitoring, and patch guidance.
Pomerium versions before 0.26.1 expose OAuth2 access and ID tokens on the user info page, allowing potential token theft. This affects organizations u...
Jul 2, 2024CVE-2023-33189 is an authorization bypass vulnerability in Pomerium identity-aware access proxy. Attackers can craft requests to bypass authorization ...
May 30, 2023CVE-2021-39206 is an authorization bypass vulnerability in Pomerium's underlying Envoy proxy that could allow specially crafted requests to bypass pat...
Sep 9, 2021This CVE describes a denial-of-service vulnerability in Envoy's HTTP/2 stream reset handling that affects Pomerium identity-aware access proxies. Atta...
Sep 9, 2021Why Monitor Pomerium Security Vulnerabilities?
Real-time CVE tracking: Our automated system monitors 4+ known vulnerabilities affecting Pomerium products and software packages. Stay ahead of emerging threats with instant email notifications when new security issues are discovered.
Automated security monitoring: Unlike manual CVE checking, FixTheCVE automatically scans your servers and detects vulnerable Pomerium packages in under 60 seconds. No agents required - completely agentless scanning that works across Pomerium deployments.
Free vulnerability database: Access detailed information about every Pomerium CVE including CVSS scores, severity ratings, affected versions, and actionable patch guidance. Filter by critical, high, medium, or low severity to prioritize your security remediation efforts.
🚀 Get Started in 60 Seconds
- Register free account & add your servers
- Run one-time scan or schedule automatic monitoring (every 1-24 hours)
- Receive instant alerts when new Pomerium CVEs affect your systems
- Access dashboard with severity breakdown & fix instructions