Skip to main content
Loading…
    CVE-2026-31381 — An attacker can extract user email addresses (PII) exposed in base64 encoding via the state parameter in the OAuth callback URL. — CVE Database · The Intelligence Room