GHSA-rf2w-6p6m-3cqvMediumCVSS 4.3
A vulnerability was found in trinodb trino 481. Affected is an unknown function of the file core...
🔗 CVE IDs covered (1)
📋 Description
A vulnerability was found in trinodb trino 481. Affected is an unknown function of the file core/trino-main/src/main/java/io/trino/server/ExternalUriInfo.java of the component OAuth2/OIDC. Performing a manipulation of the argument redirect_uri results in open redirect. It is possible to initiate the attack remotely. The project was informed of the problem early through an issue report but has not responded yet.
🔗 References (8)
- https://nvd.nist.gov/vuln/detail/CVE-2026-16336
- https://github.com/trinodb/trino/issues/29754
- https://github.com/trinodb/trino
- https://vuldb.com/cve/CVE-2026-16336
- https://vuldb.com/submit/858687
- https://vuldb.com/vuln/380710
- https://vuldb.com/vuln/380710/cti
- https://github.com/advisories/GHSA-rf2w-6p6m-3cqv