Subaddressing Vulnerability in Logto Authentication Infrastructure
CVE-2026-62317

7.5HIGH

Key Information:

Vendor

Logto-io

Status
Vendor
CVE Published:
19 August 2026

What is CVE-2026-62317?

Logto, an open-source authentication infrastructure for SaaS and AI applications, features a vulnerability related to its email subaddressing blocklist. Before version 1.41.0, the system allowed for the construction of subaddressing regular expressions using attacker-controlled email inputs when blockSubaddressing was enabled. This permissive regex could lead to catastrophic backtracking, overwhelming the event loop and potentially rendering critical functions such as authentication, token issuance, and Single Sign-On (SSO) unavailable. Users are advised to upgrade to version 1.41.0 or later to remediate this issue.

Affected Version(s)

logto < 1.41.0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.