CVE-2026-31381
An attacker can extract user email addresses (PII) exposed in base64 encoding via the state parameter in the OAuth callb
An attacker can extract user email addresses (PII) exposed in base64 encoding via the state parameter in the OAuth callback URL.
MEDIUM · CVSS 5.3
EPSS 0.00014
Schedule remediation
- SSVC automatable: yes - attacks can be scripted at scale
Sigma rules0
YARA rules0