---
id: CVE-2026-82263
title: >-
  Logto through 1.42.0 contains a server-side request forgery vulnerability in
  the OIDC SSO connector creation endpoint that fails to validate the issuer URL
  parameter
summary: >-
  Logto through 1.42.0 contains a server-side request forgery vulnerability in
  the OIDC SSO connector creation endpoint that fails to validate the issuer URL
  parameter. Tenant administrators with Management API credentials can supply
  arbit…
severity: medium
cvss: 6.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N'
cwe:
  - CWE-918
published: '2026-08-28'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T20:23:49.880'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-82263'
references:
  - url: 'https://github.com/logto-io/logto'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/logto-io/logto/blob/v1.42.0/packages/core/src/sso/OidcConnector/utils.ts
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/logto-io/logto/commit/16f4b2e732d5114ac98646c9370ec6ab61d6ed26
    label: disclosure@vulncheck.com
  - url: 'https://github.com/logto-io/logto/issues/9465'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/logto-server-side-request-forgery-via-oidc-sso-connector-issuer-url
    label: disclosure@vulncheck.com
  - url: 'https://github.com/logto-io/logto/issues/9465'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
epss: 0.00459
epssPercentile: 0.37083
ingestedAt: '2026-09-08T21:11:12.287Z'
vendor: logto-io
product: logto
affected:
  - logto <= 1.42.0
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-08-28T20:23:06.328291Z'
---

## Overview

Logto through 1.42.0 contains a server-side request forgery vulnerability in the OIDC SSO connector creation endpoint that fails to validate the issuer URL parameter. Tenant administrators with Management API credentials can supply arbitrary internal URLs to trigger HTTP GET requests to private network services, with response content returned in API responses.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
