HIGH 8.6 Go

Octo STS Unauthenticated SSRF by abusing fields in OpenID Connect tokens

GHSA-h3qp-hwvr-9xcq · CVE-2025-52477 · GO-2025-3779

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Summary

Octo-STS versions before v0.5.3 are vulnerable to unauthenticated SSRF by abusing fields in OpenID Connect tokens. Malicious tokens were shown to trigger internal network requests which could reflect error logs with sensitive information.

Please upgrade to v0.5.3 to resolve this issue. This version includes patch sets to sanitize input and redact logging.

Many thanks to @vicevirus for reporting this issue and for assisting with remediation review.

References

Ready to move

Start Securing

Free, no credit card | First findings in minutes