Skip to content
OpenBaoGHSA-cpj3-3r2f-xj59

OpenBao has Reflected XSS in its OIDC authentication error message

CriticalCVE-2026-33758 · Published Mar 26, 2026 · updated Jul 27, 2026

### Impact OpenBao installations that have an OIDC/JWT authentication method enabled and a role with `callback_mode=direct` configured are vulnerable to XSS via the `error_description` parameter on the page for a failed authentication. This allows an attacker access to the token used in the Web UI by a victim. ### Patches The `error_description` parameter has been replaced with a static error message in v2.5.2 ### Workarounds The vulnerability can be mitigated by removing any roles with `callback_mode` set to `direct`.

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/openbao/openbao
Go
< 0.0.0-20260325133417-6e2b2dd84f0e0.0.0-20260325133417-6e2b2dd84f0e
Details and references

More OpenBao advisories

All OpenBao
Advisory
OpenBao's Namespace Deletion May Not Delete Data Properly
LowMay 5
OpenBao's Token Store Allows Cross-Namespace Renewal, Revocation
LowApr 21
OpenBao's SQL Injection in PostgreSQL database secrets engine
Medium4.9Apr 21
OpenBao: Decompression Bomb via Unbounded Copy in OCI Plugin Extraction (DoS)
Low3.1Apr 21
OpenBao's Certificate Authentication Allows Token Renewal With Different Certificate
Low3.1Apr 21
OpenBao lacks user confirmation for OIDC direct callback mode
Critical9.6Mar 26

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.