OpenAM before 16.1.3 contains an open redirect vulnerability that allows unauthenticated...

zetlyn/cve-ghsa vulnerability ghsa GHSA-mxvw-rw3m-5c33 cve CVE-2026-105118 known 2026-10-03

https://github.com/advisories/GHSA-mxvw-rw3m-5c33

Properties

cvss4.7
receipt
Source
GitHub advisories
Its words
4.7
Read by
field:cvss.score
Said since
2026-10-03 18:07 UTC
Last answered
2026-10-06 13:46 UTC
Original
open at the source
What the source handed over
{
  "comments": 0,
  "credits": [],
  "cve_id": "CVE-2026-105118",
  "cvss": {
    "score": 4.7,
    "vector_string": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N"
  },
  "cvss_severities": {
    "cvss_v3": {
      "score": 4.7,
      "vector_string": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N"
    },
    "cvss_v4": {
      "score": 2.3,
      "vector_string": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
    }
  },
  "cwes": [
    {
      "cwe_id": "CWE-347",
      "name": "Improper Verification of Cryptographic Signature"
    }
  ],
  "description": "OpenAM before 16.1.3 contains an open redirect vulnerability that allows unauthenticated attackers to redirect users by supplying an unverified id_token_hint to the /oauth2/connect/endSession endpoint. Attackers can name any realm client in a forged hint to redirect victims to any registered post-logout URI, enabling phishing that borrows the OpenAM host's trust.",
  "ghsa_id": "GHSA-mxvw-rw3m-5c33",
  "github_reviewed_at": null,
  "html_url": "https://github.com/advisories/GHSA-mxvw-rw3m-5c33",
  "identifiers": [
    {
      "type": "GHSA",
      "value": "GHSA-mxvw-rw3m-5c33"
    },
    {
      "type": "CVE",
      "value": "CVE-2026-105118"
    }
  ],
  "nvd_published_at": "2026-10-03T14:16:38Z",
  "published_at": "2026-10-03T15:30:25Z",
  "references": [
    "https://github.com/OpenIdentityPlatform/OpenAM/security/advisories/GHSA-6f8c-crwq-jqm3",
    "https://nvd.nist.gov/vuln/detail/CVE-2026-105118",
    "https://www.vulncheck.com/advisories/openam-before-16.1.3-open-redirect-via-unverified-id-token-hint-in-endsession",
    "https://github.com/advisories/GHSA-mxvw-rw3m-5c33"
  ],
  "repository_advisory_url": null,
  "severity": "low",
  "source_code_location": "",
  "summary": "OpenAM before 16.1.3 contains an open redirect vulnerability that allows unauthenticated...",
  "type": "unreviewed",
  "updated_at": "2026-10-03T15:30:25Z",
  "url": "https://api.github.com/advisories/GHSA-mxvw-rw3m-5c33",
  "vulnerabilities": [],
  "withdrawn_at": null
}
cweCWE-347
receipt
Source
GitHub advisories
Its words
CWE-347
Read by
field:cwes[].cwe_id
Said since
2026-10-03 18:07 UTC
Last answered
2026-10-06 13:46 UTC
Original
open at the source
What the source handed over
{
  "comments": 0,
  "credits": [],
  "cve_id": "CVE-2026-105118",
  "cvss": {
    "score": 4.7,
    "vector_string": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N"
  },
  "cvss_severities": {
    "cvss_v3": {
      "score": 4.7,
      "vector_string": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N"
    },
    "cvss_v4": {
      "score": 2.3,
      "vector_string": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
    }
  },
  "cwes": [
    {
      "cwe_id": "CWE-347",
      "name": "Improper Verification of Cryptographic Signature"
    }
  ],
  "description": "OpenAM before 16.1.3 contains an open redirect vulnerability that allows unauthenticated attackers to redirect users by supplying an unverified id_token_hint to the /oauth2/connect/endSession endpoint. Attackers can name any realm client in a forged hint to redirect victims to any registered post-logout URI, enabling phishing that borrows the OpenAM host's trust.",
  "ghsa_id": "GHSA-mxvw-rw3m-5c33",
  "github_reviewed_at": null,
  "html_url": "https://github.com/advisories/GHSA-mxvw-rw3m-5c33",
  "identifiers": [
    {
      "type": "GHSA",
      "value": "GHSA-mxvw-rw3m-5c33"
    },
    {
      "type": "CVE",
      "value": "CVE-2026-105118"
    }
  ],
  "nvd_published_at": "2026-10-03T14:16:38Z",
  "published_at": "2026-10-03T15:30:25Z",
  "references": [
    "https://github.com/OpenIdentityPlatform/OpenAM/security/advisories/GHSA-6f8c-crwq-jqm3",
    "https://nvd.nist.gov/vuln/detail/CVE-2026-105118",
    "https://www.vulncheck.com/advisories/openam-before-16.1.3-open-redirect-via-unverified-id-token-hint-in-endsession",
    "https://github.com/advisories/GHSA-mxvw-rw3m-5c33"
  ],
  "repository_advisory_url": null,
  "severity": "low",
  "source_code_location": "",
  "summary": "OpenAM before 16.1.3 contains an open redirect vulnerability that allows unauthenticated...",
  "type": "unreviewed",
  "updated_at": "2026-10-03T15:30:25Z",
  "url": "https://api.github.com/advisories/GHSA-mxvw-rw3m-5c33",
  "vulnerabilities": [],
  "withdrawn_at": null
}
severitylow
Below 4.0.
receipt
Source
GitHub advisories
Its words
low
Read by
field:severity
Said since
2026-10-03 18:07 UTC
Last answered
2026-10-06 13:46 UTC
Original
open at the source
What the source handed over
{
  "comments": 0,
  "credits": [],
  "cve_id": "CVE-2026-105118",
  "cvss": {
    "score": 4.7,
    "vector_string": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N"
  },
  "cvss_severities": {
    "cvss_v3": {
      "score": 4.7,
      "vector_string": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N"
    },
    "cvss_v4": {
      "score": 2.3,
      "vector_string": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
    }
  },
  "cwes": [
    {
      "cwe_id": "CWE-347",
      "name": "Improper Verification of Cryptographic Signature"
    }
  ],
  "description": "OpenAM before 16.1.3 contains an open redirect vulnerability that allows unauthenticated attackers to redirect users by supplying an unverified id_token_hint to the /oauth2/connect/endSession endpoint. Attackers can name any realm client in a forged hint to redirect victims to any registered post-logout URI, enabling phishing that borrows the OpenAM host's trust.",
  "ghsa_id": "GHSA-mxvw-rw3m-5c33",
  "github_reviewed_at": null,
  "html_url": "https://github.com/advisories/GHSA-mxvw-rw3m-5c33",
  "identifiers": [
    {
      "type": "GHSA",
      "value": "GHSA-mxvw-rw3m-5c33"
    },
    {
      "type": "CVE",
      "value": "CVE-2026-105118"
    }
  ],
  "nvd_published_at": "2026-10-03T14:16:38Z",
  "published_at": "2026-10-03T15:30:25Z",
  "references": [
    "https://github.com/OpenIdentityPlatform/OpenAM/security/advisories/GHSA-6f8c-crwq-jqm3",
    "https://nvd.nist.gov/vuln/detail/CVE-2026-105118",
    "https://www.vulncheck.com/advisories/openam-before-16.1.3-open-redirect-via-unverified-id-token-hint-in-endsession",
    "https://github.com/advisories/GHSA-mxvw-rw3m-5c33"
  ],
  "repository_advisory_url": null,
  "severity": "low",
  "source_code_location": "",
  "summary": "OpenAM before 16.1.3 contains an open redirect vulnerability that allows unauthenticated...",
  "type": "unreviewed",
  "updated_at": "2026-10-03T15:30:25Z",
  "url": "https://api.github.com/advisories/GHSA-mxvw-rw3m-5c33",
  "vulnerabilities": [],
  "withdrawn_at": null
}

Text

OpenAM before 16.1.3 contains an open redirect vulnerability that allows unauthenticated... OpenAM before 16.1.3 contains an open redirect vulnerability that allows unauthenticated attackers to redirect users by supplying an unverified id_token_hint to the /oauth2/connect/endSession endpoint. Attackers can name any realm client in a forged hint to redirect victims to any registered post-logout URI, enabling phishing that borrows the OpenAM host's trust.