Subaddressing Vulnerability in Logto Authentication Infrastructure
CVE-2026-62317
7.5HIGH
What is CVE-2026-62317?
Logto, an open-source authentication infrastructure for SaaS and AI applications, features a vulnerability related to its email subaddressing blocklist. Before version 1.41.0, the system allowed for the construction of subaddressing regular expressions using attacker-controlled email inputs when blockSubaddressing was enabled. This permissive regex could lead to catastrophic backtracking, overwhelming the event loop and potentially rendering critical functions such as authentication, token issuance, and Single Sign-On (SSO) unavailable. Users are advised to upgrade to version 1.41.0 or later to remediate this issue.
Affected Version(s)
logto < 1.41.0
