CVE Explorer
CVE-2026-33505
Ory Keto is am open source authorization server for managing permissions at scale. Prior to version 26.2.0, the GetRelationships API in Ory Keto is vulnerable to SQL injection due to flaws in its pagination implementation. Pagination tokens are encrypted using the secret configured in `secrets.pagination`. An attacker who knows this secret can craft their own tokens, including malicious tokens that lead to SQL injection. If this configuration value is not set, Keto falls back to a hard-coded def
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"keto","vendor":"ory","versions":[{"status":"affected","version":"< 26.2.0"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:ac1d6d2244c83f195e2947934e35e9c22b4d5fd6beca2a94a1f35ee6fa4f197f · sha256:348d513555f73db8… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.2,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"HIGH","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:ac1d6d2244c83f195e2947934e35e9c22b4d5fd6beca2a94a1f35ee6fa4f197f · sha256:348d513555f73db8… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-89","description":"CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:ac1d6d2244c83f195e2947934e35e9c22b4d5fd6beca2a94a1f35ee6fa4f197f · sha256:348d513555f73db8… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"name":"https://github.com/ory/keto/security/advisories/GHSA-c38g-mx2c-9wf2","tags":["x_refsource_CONFIRM"],"url":"https://github.com/ory/keto/security/advisories/GHSA-c38g-mx2c-9wf2"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:ac1d6d2244c83f195e2947934e35e9c22b4d5fd6beca2a94a1f35ee6fa4f197f · sha256:348d513555f73db8… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.