{"id":"CVE-2026-16336","summary":"trinodb trino OAuth2/OIDC ExternalUriInfo.java redirect","details":"A vulnerability was found in trinodb trino 481. Affected is an unknown function of the file core/trino-main/src/main/java/io/trino/server/ExternalUriInfo.java of the component OAuth2/OIDC. Performing a manipulation of the argument redirect_uri results in open redirect. It is possible to initiate the attack remotely. The project was informed of the problem early through an issue report but has not responded yet.","modified":"2026-08-07T11:31:18.186739448Z","published":"2026-07-21T02:30:09.393Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/16xxx/CVE-2026-16336.json","cna_assigner":"VulDB","cwe_ids":["CWE-601"]},"references":[{"type":"WEB","url":"https://github.com/trinodb/trino/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/16xxx/CVE-2026-16336.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-16336"},{"type":"ADVISORY","url":"https://vuldb.com/cve/CVE-2026-16336"},{"type":"ADVISORY","url":"https://vuldb.com/submit/858687"},{"type":"ADVISORY","url":"https://vuldb.com/vuln/380710"},{"type":"REPORT","url":"https://github.com/trinodb/trino/issues/29754"},{"type":"REPORT","url":"https://vuldb.com/vuln/380710/cti"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/trinodb/trino","events":[{"introduced":"c4ac66cb4f86728b48f15b10d6ab3c1aa0166d3c"},{"last_affected":"c4ac66cb4f86728b48f15b10d6ab3c1aa0166d3c"}],"database_specific":{"extracted_events":[{"introduced":"481"},{"last_affected":"481"}],"source":"AFFECTED_FIELD"}}],"versions":["481"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-16336.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X"}]}