HIGH GitHub
CVE-2026-35511
Authorizer: Zero-click account takeover via OAuth identity linking to unverified email accounts
The OAuth callback handler links incoming OAuth identities (Google, GitHub, etc.) to existing accounts matched by email address without verifying that the existing account's email was verified by its original owner. An attacker who pre-registers with a victim's email address (without verifying it) gains persistent password-based access to the victim's account after the victim completes a normal OAuth login. Verified against HEAD (commit 73679fa).
## Root Cause
In `internal/http_handlers/oauth_
Affected Products
- go/github.com/authorizerdev/authorizer < 0.0.0-20260807033110-66fe488fd2a4
References
- https://github.com/advisories/GHSA-29rf-f4vv-pvq6
- https://github.com/authorizerdev/authorizer/security/advisories/GHSA-29rf-f4vv-pvq6
- https://github.com/authorizerdev/authorizer/commit/66fe488fd2a4e7acf1e517334344d5e8f3ddd29
- https://github.com/authorizerdev/authorizer/releases/tag/2.4.0-rc.16
This high severity vulnerability was published on 2026-08-14 via GitHub. Affected: go/github.com/authorizerdev/authorizer < 0.0.0-20260807033110-66fe488fd2a4.
vulnfeed aggregates 9887 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.