Back to overview

CVE-2026-16336

MEDIUM
4.3
CVSS 3.1
Description
A vulnerability was found in trinodb trino 481. Affected is an unknown function of the file core/trino-main/src/main/java/io/trino/server/ExternalUriInfo.java of the component OAuth2/OIDC. Performing a manipulation of the argument redirect_uri results in open redirect. It is possible to initiate the attack remotely. The project was informed of the problem early through an issue report but has not responded yet.

Metadata

CVE ID
CVE-2026-16336
State
PUBLISHED
Assigner
VulDB
Reserved
2026-07-20 18:06 UTC
Published
2026-07-21 02:30 UTC
Last updated
2026-07-21 02:30 UTC
Primary CWE
CWE-601
Open Redirect
Vendor / Product
trinodb / trino
Sources
cve.org  ·  NVD

Severity & Metrics

4.3 MEDIUM CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:X/RL:X/RC:R
Affected products (1)
VendorProductPlatformVersions
trinodb trino 481
Weakness (CWE)
CWESourceDescription
CWE-601 cna Open Redirect
CVSS scores (4)
ScoreSeverityVersionSourceVector
5.3 MEDIUM 4.0 cna CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X
5.0 N/D 2.0 cna AV:N/AC:L/Au:N/C:N/I:P/A:N/E:ND/RL:ND/RC:UR
4.3 MEDIUM 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:X/RL:X/RC:R
4.3 MEDIUM 3.0 cna CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:X/RL:X/RC:R
References (6)
Back to overview