Open Redirect Vulnerability in Trino by TrinoDB
CVE-2026-16336
5.3MEDIUM
What is CVE-2026-16336?
A vulnerability exists in the OAuth2/OIDC component of Trino (version 481), specifically within the ExternalUriInfo.java file. This flaw allows unauthenticated users to manipulate the redirect_uri parameter, which can lead to open redirect issues. Attackers can exploit this vulnerability remotely, redirecting users to malicious sites without proper validation. Despite an early report of the issue, there has been no response from the TrinoDB project team regarding a fix or mitigation measures.
Affected Version(s)
trino 481
