CVE-2018-8899: Identityserver IDENTITYSERVER4

Medium severity, CVSS 6.1. EPSS: 1.2% chance of exploitation in the next 30 days.

IdentityServer IdentityServer4 1.x before 1.5.3 and 2.x before 2.1.3 does not encode the redirect URI on the authorization response page, which might lead to XSS in some configurations.

Affected products

  • Identityserver IDENTITYSERVER4: from 1.0.0, up to and including 1.5.2; from 2.0.0, up to and including 2.1.2

Published 2018-03-22. Last modified 2026-06-17.