CVE-2026-82263: Logto Server-Side Request Forgery via OIDC SSO Connector Issuer URL
Logto through 1.42.0 contains a server-side request forgery vulnerability in the OIDC SSO connector creation endpoint that fails to validate the issuer URL parameter. Tenant administrators with Management API credentials can supply arbitrary internal URLs to trigger HTTP GET requests to private network services, with response content returned in API responses.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs tenant-administrator privileges and Management API credentials. The vulnerable action is creating an OIDC SSO connector with a controlled issuer URL.
What access can an attacker gain through the vulnerable request?
The attacker can cause the Logto server to send HTTP GET requests to arbitrary internal URLs. Response content from the targeted private network service is returned in API responses, exposing data reachable by the server.
Which versions are affected?
Logto through version 1.42.0 is affected. The provided information does not identify a fixed version.