Skip to content

OpenAM Pre-authentication Reflected XSS OAuth2 / OIDC

High
vharseko published GHSA-fq9h-c788-fx73 Jun 21, 2026

Package

maven org.openidentityplatform.openam:openam-oauth2 (Maven)

Affected versions

13>= <=16.0.6

Patched versions

16.1.1

Description

1. Summary

The OAuth 2.0 / OpenID Connect authorization endpoint does not sufficiently sanitize certain user-supplied parameters before incorporating them into the HTML response generated for the form_post response mode. This may allow an attacker to inject content into the rendered page in the context of the OpenAM origin.

Severity

High

CVE ID

CVE-2026-44203

Weaknesses

No CWEs

Credits