OpenAM before 16.1.3 contains an open redirect vulnerability that allows unauthenticated...
zetlyn/cve-ghsa vulnerability ghsa GHSA-mxvw-rw3m-5c33 cve CVE-2026-105118 known 2026-10-03
https://github.com/advisories/GHSA-mxvw-rw3m-5c33
Properties
| cvss | 4.7receipt
What the source handed over{
"comments": 0,
"credits": [],
"cve_id": "CVE-2026-105118",
"cvss": {
"score": 4.7,
"vector_string": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N"
},
"cvss_severities": {
"cvss_v3": {
"score": 4.7,
"vector_string": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N"
},
"cvss_v4": {
"score": 2.3,
"vector_string": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
},
"cwes": [
{
"cwe_id": "CWE-347",
"name": "Improper Verification of Cryptographic Signature"
}
],
"description": "OpenAM before 16.1.3 contains an open redirect vulnerability that allows unauthenticated attackers to redirect users by supplying an unverified id_token_hint to the /oauth2/connect/endSession endpoint. Attackers can name any realm client in a forged hint to redirect victims to any registered post-logout URI, enabling phishing that borrows the OpenAM host's trust.",
"ghsa_id": "GHSA-mxvw-rw3m-5c33",
"github_reviewed_at": null,
"html_url": "https://github.com/advisories/GHSA-mxvw-rw3m-5c33",
"identifiers": [
{
"type": "GHSA",
"value": "GHSA-mxvw-rw3m-5c33"
},
{
"type": "CVE",
"value": "CVE-2026-105118"
}
],
"nvd_published_at": "2026-10-03T14:16:38Z",
"published_at": "2026-10-03T15:30:25Z",
"references": [
"https://github.com/OpenIdentityPlatform/OpenAM/security/advisories/GHSA-6f8c-crwq-jqm3",
"https://nvd.nist.gov/vuln/detail/CVE-2026-105118",
"https://www.vulncheck.com/advisories/openam-before-16.1.3-open-redirect-via-unverified-id-token-hint-in-endsession",
"https://github.com/advisories/GHSA-mxvw-rw3m-5c33"
],
"repository_advisory_url": null,
"severity": "low",
"source_code_location": "",
"summary": "OpenAM before 16.1.3 contains an open redirect vulnerability that allows unauthenticated...",
"type": "unreviewed",
"updated_at": "2026-10-03T15:30:25Z",
"url": "https://api.github.com/advisories/GHSA-mxvw-rw3m-5c33",
"vulnerabilities": [],
"withdrawn_at": null
} |
|---|---|
| cwe | CWE-347receipt
What the source handed over{
"comments": 0,
"credits": [],
"cve_id": "CVE-2026-105118",
"cvss": {
"score": 4.7,
"vector_string": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N"
},
"cvss_severities": {
"cvss_v3": {
"score": 4.7,
"vector_string": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N"
},
"cvss_v4": {
"score": 2.3,
"vector_string": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
},
"cwes": [
{
"cwe_id": "CWE-347",
"name": "Improper Verification of Cryptographic Signature"
}
],
"description": "OpenAM before 16.1.3 contains an open redirect vulnerability that allows unauthenticated attackers to redirect users by supplying an unverified id_token_hint to the /oauth2/connect/endSession endpoint. Attackers can name any realm client in a forged hint to redirect victims to any registered post-logout URI, enabling phishing that borrows the OpenAM host's trust.",
"ghsa_id": "GHSA-mxvw-rw3m-5c33",
"github_reviewed_at": null,
"html_url": "https://github.com/advisories/GHSA-mxvw-rw3m-5c33",
"identifiers": [
{
"type": "GHSA",
"value": "GHSA-mxvw-rw3m-5c33"
},
{
"type": "CVE",
"value": "CVE-2026-105118"
}
],
"nvd_published_at": "2026-10-03T14:16:38Z",
"published_at": "2026-10-03T15:30:25Z",
"references": [
"https://github.com/OpenIdentityPlatform/OpenAM/security/advisories/GHSA-6f8c-crwq-jqm3",
"https://nvd.nist.gov/vuln/detail/CVE-2026-105118",
"https://www.vulncheck.com/advisories/openam-before-16.1.3-open-redirect-via-unverified-id-token-hint-in-endsession",
"https://github.com/advisories/GHSA-mxvw-rw3m-5c33"
],
"repository_advisory_url": null,
"severity": "low",
"source_code_location": "",
"summary": "OpenAM before 16.1.3 contains an open redirect vulnerability that allows unauthenticated...",
"type": "unreviewed",
"updated_at": "2026-10-03T15:30:25Z",
"url": "https://api.github.com/advisories/GHSA-mxvw-rw3m-5c33",
"vulnerabilities": [],
"withdrawn_at": null
} |
| severity | low Below 4.0. receipt
What the source handed over{
"comments": 0,
"credits": [],
"cve_id": "CVE-2026-105118",
"cvss": {
"score": 4.7,
"vector_string": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N"
},
"cvss_severities": {
"cvss_v3": {
"score": 4.7,
"vector_string": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N"
},
"cvss_v4": {
"score": 2.3,
"vector_string": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
},
"cwes": [
{
"cwe_id": "CWE-347",
"name": "Improper Verification of Cryptographic Signature"
}
],
"description": "OpenAM before 16.1.3 contains an open redirect vulnerability that allows unauthenticated attackers to redirect users by supplying an unverified id_token_hint to the /oauth2/connect/endSession endpoint. Attackers can name any realm client in a forged hint to redirect victims to any registered post-logout URI, enabling phishing that borrows the OpenAM host's trust.",
"ghsa_id": "GHSA-mxvw-rw3m-5c33",
"github_reviewed_at": null,
"html_url": "https://github.com/advisories/GHSA-mxvw-rw3m-5c33",
"identifiers": [
{
"type": "GHSA",
"value": "GHSA-mxvw-rw3m-5c33"
},
{
"type": "CVE",
"value": "CVE-2026-105118"
}
],
"nvd_published_at": "2026-10-03T14:16:38Z",
"published_at": "2026-10-03T15:30:25Z",
"references": [
"https://github.com/OpenIdentityPlatform/OpenAM/security/advisories/GHSA-6f8c-crwq-jqm3",
"https://nvd.nist.gov/vuln/detail/CVE-2026-105118",
"https://www.vulncheck.com/advisories/openam-before-16.1.3-open-redirect-via-unverified-id-token-hint-in-endsession",
"https://github.com/advisories/GHSA-mxvw-rw3m-5c33"
],
"repository_advisory_url": null,
"severity": "low",
"source_code_location": "",
"summary": "OpenAM before 16.1.3 contains an open redirect vulnerability that allows unauthenticated...",
"type": "unreviewed",
"updated_at": "2026-10-03T15:30:25Z",
"url": "https://api.github.com/advisories/GHSA-mxvw-rw3m-5c33",
"vulnerabilities": [],
"withdrawn_at": null
} |
Text
OpenAM before 16.1.3 contains an open redirect vulnerability that allows unauthenticated...
OpenAM before 16.1.3 contains an open redirect vulnerability that allows unauthenticated attackers to redirect users by supplying an unverified id_token_hint to the /oauth2/connect/endSession endpoint. Attackers can name any realm client in a forged hint to redirect victims to any registered post-logout URI, enabling phishing that borrows the OpenAM host's trust.