RFC 9700. Describes security requirements and recommendations for clients and servers implementing OAuth 2.0. Supersedes earlier guidance and reflects current best practices.
RFC 6819. Documents known attacks against OAuth 2.0 — both theoretical and demonstrated — along with countermeasures for each.
The OAuth community is committed to identifying and addressing any security issues raised relating to the OAuth protocol and extensions. Due to the nature of many security threats, they cannot be disclosed before sufficient notice is given to vulnerable parties.
Please report any concerns with specific products to the vendor of that product using their own vulnerability reporting mechanisms. For concerns related to the spec itself, refer to the IETF Guidance on Reporting Protocol Vulnerabilities.
The OAuth Security Workshop (OSW) aims to improve the security of OAuth and related Internet protocols through direct exchange between academic researchers, IETF OAuth Working Group members, and industry.