๐Ÿ” CVE Alert

CVE-2026-105122

MEDIUM 5.4

OpenAM before 16.1.3 SSRF via OpenID Connect Client jwks_uri

CVSS Score
5.4
EPSS Score
0.0%
EPSS Percentile
0th

OpenAM before 16.1.3 contains a server-side request forgery vulnerability that allows attackers able to register or modify OAuth 2.0 clients to make OpenAM fetch internal resources via an unvalidated jwks_uri. Attackers can trigger unauthenticated fetches through client-authentication and ID-token validation to probe internal hosts, metadata endpoints or local files, or exhaust request threads for denial of service.

CWE CWE-918
Vendor openidentityplatform
Product openam
Published Oct 3, 2026
Stay Ahead of the Next One

Get instant alerts for openidentityplatform openam

Be the first to know when new medium vulnerabilities affecting openidentityplatform openam are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
Low

Affected Versions

OpenIdentityPlatform / OpenAM
0 < 16.1.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/OpenIdentityPlatform/OpenAM/security/advisories/GHSA-g7cv-hh35-cc7c vulncheck.com: https://www.vulncheck.com/advisories/openam-before-16.1.3-ssrf-via-openid-connect-client-jwks-uri

Credits

๐Ÿ” arpitjain099 ๐Ÿ” santhreal ๐Ÿ” alex-sc ๐Ÿ” jamesbishup ๐Ÿ” ayhambashtawi2-lang maximthomas tsujiguchitky