HIGH GitHub

CVE-2026-35511

Authorizer: Zero-click account takeover via OAuth identity linking to unverified email accounts

The OAuth callback handler links incoming OAuth identities (Google, GitHub, etc.) to existing accounts matched by email address without verifying that the existing account's email was verified by its original owner. An attacker who pre-registers with a victim's email address (without verifying it) gains persistent password-based access to the victim's account after the victim completes a normal OAuth login. Verified against HEAD (commit 73679fa). ## Root Cause In `internal/http_handlers/oauth_

Affected Products

References

Published: 2026-08-14 · Source: GitHub · Feed updated: 2026-08-14
This high severity vulnerability was published on 2026-08-14 via GitHub. Affected: go/github.com/authorizerdev/authorizer < 0.0.0-20260807033110-66fe488fd2a4.
vulnfeed aggregates 9887 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.