OSV 1.4.0 · github-reviewed · 修改于 2026-06-23 04:11
发布时间
2026-06-23 04:11
GitHub 审查时间
2026-06-23 04:11
NVD 发布时间
—
源文件
advisories/github-reviewed/2026/06/GHSA-fq9h-c788-fx73/GHSA-fq9h-c788-fx73.json
The OAuth 2.0 / OpenID Connect authorization endpoint does not sufficiently sanitize certain user-supplied parameters before incorporating them into the HTML response generated for the form_post response mode. This may allow an attacker to inject content into the rendered page in the context of the OpenAM origin.