Vulnerability  ·  2026-09-25

Logto webhook/OAuth/OIDC outbound fetch reaches cloud-metadata and special-use addresses (SSRF, CVE-2026-56739, CVSS 8.5)

VulnerabilityMedium impactGlobalCVE-2026-56739
Logto <1.43.0 fetches administrator-controlled outbound destinations (webhook delivery, custom OAuth2 userInfoEndpoint forwarding the OAuth access token in the Authorization header, OIDC jwksUri) without validating the connection address, so webhooks/connectors can reach special-use and cloud-metadata addresses and expose internal data or upstream provider credentials. Fixed in 1.43.0.
In AI app auth infrastructure, cloud-metadata (IMDS) reachable from authenticated admin-driven outbound fetches can be used to pivot to instance credentials that AI workloads hold, and OAuth2 connectors forward user access tokens to attacker-selected endpoints - SSRF plus OAuth token exfiltration in the auth layer of AI apps.
Administrator-configured webhook/connector URL targets special-use or cloud-metadata addresses, or attacker-selected userInfoEndpoint/jwksUri forwards OAuth tokens during connector fetch.
Logto < 1.43.0 (AI/auth infrastructure)
Upgrade to Logto 1.43.0+; validate/SSRF-guard outbound hook destinations.
NVD CVE-2026-56739Logto advisory GHSA-3556-624q-c5w3
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →