No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 28 Aug 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Logto-io
Logto-io logto |
|
| Vendors & Products |
Logto-io
Logto-io logto |
|
| Metrics |
ssvc
|
Fri, 28 Aug 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Logto through 1.42.0 contains a server-side request forgery vulnerability in the OIDC SSO connector creation endpoint that fails to validate the issuer URL parameter. Tenant administrators with Management API credentials can supply arbitrary internal URLs to trigger HTTP GET requests to private network services, with response content returned in API responses. | |
| Title | Logto Server-Side Request Forgery via OIDC SSO Connector Issuer URL | |
| Weaknesses | CWE-918 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-28T20:23:27.541Z
Reserved: 2026-08-28T11:12:28.377Z
Link: CVE-2026-82263
Updated: 2026-08-28T20:23:23.850Z
Status : Received
Published: 2026-08-28T20:20:16.790
Modified: 2026-08-28T22:16:55.487
Link: CVE-2026-82263
No data.
OpenCVE Enrichment
Updated: 2026-08-28T22:15:04Z