Vulnerability Description
OpenAM before 16.1.3 contains a server-side request forgery vulnerability that allows attackers able to register or modify OAuth 2.0 clients to make OpenAM fetch internal resources via an unvalidated jwks_uri. Attackers can trigger unauthenticated fetches through client-authentication and ID-token validation to probe internal hosts, metadata endpoints or local files, or exhaust request threads for denial of service.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/OpenIdentityPlatform/OpenAM/security/advisories/GHSA-g7cv-hh3
- https://www.vulncheck.com/advisories/openam-before-16.1.3-ssrf-via-openid-connec
FAQ
What is CVE-2026-105122?
CVE-2026-105122 is a vulnerability with a CVSS score of 5.4 (MEDIUM). OpenAM before 16.1.3 contains a server-side request forgery vulnerability that allows attackers able to register or modify OAuth 2.0 clients to make OpenAM fetch internal resources via an unvalidated ...
How severe is CVE-2026-105122?
CVE-2026-105122 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-105122?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.