What is CVE-2026-62317?
CVE-2026-62317 is a vulnerability in Logto's email subaddressing blocklist affecting versions prior to 1.41.0. An attacker can craft an email input to manipulate the subaddressingRegex, potentially bypassing email-blocking policies. Users should immediately upgrade to version 1.41.0 or later to mitigate the issue.
Azərbaycanca: CVE-2026-62317 Logto autentifikasiya sistemində email subaddressing blocklist zəifliyidir. 1.41.0 versiyasından əvvəlki versiyalar təsirə məruz qalır, burada təcavüzkarın idarə etdiyi domen əsasında qurulan regex email bloklayışını yan keçə bilər. İstifadəçilər dərhal 1.41.0 və ya daha yuxarı versiyaya yeniləməlidir.
Related CVEs
link basis: shared vendor: Logto
FAQ2
Which versions of Logto are affected by CVE-2026-62317?
CVE-2026-62317 affects all versions of Logto prior to version 1.41.0.
How can I mitigate the CVE-2026-62317 vulnerability?
Users should immediately upgrade to Logto version 1.41.0 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.