CVE-2023-33189: Pomerium
Critical severity, CVSS 9.8. EPSS: 0.9% chance of exploitation in the next 30 days.
Pomerium is an identity and context-aware access proxy. With specially crafted requests, incorrect authorization decisions may be made by Pomerium. This issue has been patched in versions 0.17.4, 0.18.1, 0.19.2, 0.20.1, 0.21.4 and 0.22.2.
Affected products
- Pomerium Pomerium: before 0.17.4 (fixed in 0.17.4); from 0.19.0, before 0.19.2 (fixed in 0.19.2); from 0.21.0, before 0.21.4 (fixed in 0.21.4); from 0.22.0, before 0.22.2 (fixed in 0.22.2); version 0.18.0 only; version 0.20.0 only
Published 2023-05-30. Last modified 2026-06-17.