CyberSec.Space Logo
Back to CVE Browser

CVE-2026-50629

MEDIUM
5.3
CVSS Severity Score
EPSS Score0.0810%
EPSS Percentile2.33th
PublishedJun 12, 2026
Last ModifiedJun 12, 2026

Vulnerability Description

The 'clientId' parameter from incoming HTTP requests is directly concatenated into OAuth2 server log warning messages without sanitizing control characters. This allows an attacker to inject arbitrary content, including fake log entries, into the server's log files. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fixes this issue.

Affected Platforms (CPE)

No CPE configurations currently published for this record.

References & Advisories

Related Vulnerabilities