๐Ÿ” CVE Alert

CVE-2026-16336

MEDIUM 4.3

trinodb trino OAuth2/OIDC ExternalUriInfo.java redirect

CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th

A vulnerability was found in trinodb trino 481. Affected is an unknown function of the file core/trino-main/src/main/java/io/trino/server/ExternalUriInfo.java of the component OAuth2/OIDC. Performing a manipulation of the argument redirect_uri results in open redirect. It is possible to initiate the attack remotely. The project was informed of the problem early through an issue report but has not responded yet.

CWE CWE-601
Vendor trinodb
Product trino
Published Jul 21, 2026
Stay Ahead of the Next One

Get instant alerts for trinodb trino

Be the first to know when new medium vulnerabilities affecting trinodb trino are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:X/RL:X/RC:R
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

trinodb / trino
481

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/vuln/380710 vuldb.com: https://vuldb.com/vuln/380710/cti vuldb.com: https://vuldb.com/cve/CVE-2026-16336 vuldb.com: https://vuldb.com/submit/858687 github.com: https://github.com/trinodb/trino/issues/29754 github.com: https://github.com/trinodb/trino/

Credits

๐Ÿ” 0Xrry (VulDB User) VulDB CNA Team