Logto through 1.42.0 contains a server-side request forgery vulnerability in the POST /api/hooks/:id/test endpoint that accepts arbitrary URLs without host validation. Tenant administrators with Management API tokens can make the server issue HTTP POST requests to internal URLs and retrieve response bodies from services on the private network.
Metrics
Affected Vendors & Products
References
History
Fri, 28 Aug 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Logto-io
Logto-io logto |
|
| Vendors & Products |
Logto-io
Logto-io logto |
Fri, 28 Aug 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Logto through 1.42.0 contains a server-side request forgery vulnerability in the POST /api/hooks/:id/test endpoint that accepts arbitrary URLs without host validation. Tenant administrators with Management API tokens can make the server issue HTTP POST requests to internal URLs and retrieve response bodies from services on the private network. | |
| Title | Logto Server-Side Request Forgery via webhook test endpoint | |
| Weaknesses | CWE-918 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-28T16:18:47.953Z
Reserved: 2026-08-28T10:39:30.356Z
Link: CVE-2026-82262
No data.
Status : Received
Published: 2026-08-28T20:20:16.643
Modified: 2026-08-28T20:20:16.643
Link: CVE-2026-82262
No data.
OpenCVE Enrichment
Updated: 2026-08-28T22:15:04Z