Open Redirect Vulnerability in Trino by TrinoDB
CVE-2026-16336

5.3MEDIUM

Key Information:

Vendor

Trinodb

Status
Vendor
CVE Published:
21 July 2026

What is CVE-2026-16336?

A vulnerability exists in the OAuth2/OIDC component of Trino (version 481), specifically within the ExternalUriInfo.java file. This flaw allows unauthenticated users to manipulate the redirect_uri parameter, which can lead to open redirect issues. Attackers can exploit this vulnerability remotely, redirecting users to malicious sites without proper validation. Despite an early report of the issue, there has been no response from the TrinoDB project team regarding a fix or mitigation measures.

Affected Version(s)

trino 481

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

0Xrry (VulDB User)
VulDB CNA Team
.