CVE-2021-32701
NixOS vulnerability analysis and mitigation

Overview

ORY Oathkeeper, an Identity & Access Proxy (IAP) and Access Control Decision API, was found to have a security vulnerability in versions v0.38.0-beta.2 through v0.38.11-beta.1. The vulnerability allows for bypassing token claim validation when OAuth2 Introspection caching is enabled. This issue was discovered in June 2021 and was assigned CVE-2021-32701 (GitHub Advisory).

Technical details

The vulnerability occurs when making a request to an endpoint that requires a specific scope (e.g., 'foo') using an access token granted with that scope. The introspection result is cached. If a subsequent request is made to an endpoint requiring a different scope (e.g., 'bar') before the cache expires, the introspection will be considered valid regardless of whether the token has the required 'bar' scope. The issue stems from the cache only validating the token expiration date while ignoring scope validation (GitHub Advisory).

Impact

This vulnerability could allow attackers to bypass scope validation checks and access endpoints for which they don't have the required permissions, potentially leading to unauthorized access to protected resources (GitHub Advisory).

Exploitability

The vulnerability can be exploited by making sequential requests with a valid token to different endpoints with different scope requirements before the cache expires. The attack requires a valid token with at least one legitimate scope to initiate the exploit (GitHub Advisory).

Mitigation and workarounds

The vulnerability was patched in version v0.38.12-beta.1. For users unable to upgrade immediately, a workaround exists: caching is disabled by default for the oauth2_introspection authenticator, and when caching is disabled, this vulnerability does not exist. The development team has also implemented additional security measures including strict code coverage requirements and CodeQL scanning in CI to prevent similar issues (GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-13097CRITICAL9.1
  • NixOS logoNixOS
  • python3-samba-test
NoYesAug 20, 2026
CVE-2026-11861HIGH8.1
  • NixOS logoNixOS
  • samba-common
NoYesAug 20, 2026
CVE-2026-73198HIGH7.5
  • NixOS logoNixOS
  • ctdb-ceph-mutex
NoYesAug 20, 2026
CVE-2026-73197HIGH7.5
  • NixOS logoNixOS
  • samba-test-libs-debuginfo
NoYesAug 20, 2026
CVE-2026-73196MEDIUM6.5
  • NixOS logoNixOS
  • samba-ldb-ldap-modules-debuginfo
NoYesAug 20, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management