{"id":"CVE-2026-66773","summary":"Server-controlled `__next` URL is not checking cross-origin","details":"A malicious or compromised OData service could disclose sensitive authentication information and inject untrusted data into the application, which may leads to a high impact on confidentiality and low impact on integrity and no impact on Availability.","aliases":["GHSA-hc5j-q32w-c25v"],"modified":"2026-08-12T04:18:43.106473357Z","published":"2026-08-11T00:18:58.770Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/66xxx/CVE-2026-66773.json","cna_assigner":"sap","cwe_ids":["CWE-601"]},"references":[{"type":"WEB","url":"https://url.sap/sapsecuritypatchday"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/66xxx/CVE-2026-66773.json"},{"type":"ADVISORY","url":"https://github.com/SAP/python-pyodata/security/advisories/GHSA-hc5j-q32w-c25v"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-66773"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/sap/python-pyodata","events":[{"introduced":"ed7b8b07a38b46eaea3c693771265f9c4ce0b76d"},{"last_affected":"ed7b8b07a38b46eaea3c693771265f9c4ce0b76d"}],"database_specific":{"extracted_events":[{"introduced":"pyodata (pip) \u003c 1.11.2"},{"last_affected":"pyodata (pip) \u003c 1.11.2"}],"source":"AFFECTED_FIELD"}}],"versions":["pyodata (pip) \u003c 1.11.2","1.11.2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-66773.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:N"}]}