PT-2026-78644 · Logto · Logto

CVE-2026-62317

·

Published

2026-08-19

·

Updated

2026-08-21

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Logto versions prior to 1.41.0
Description When the blockSubaddressing feature is enabled, the software uses an attacker-controlled domain from the email input to construct a regular expression. Due to a permissive emailRegEx that accepts multiple at signs and regular expression metacharacters, the subaddressingRegex.test(email) function can trigger catastrophic backtracking—a state where a regular expression engine takes an exponential amount of time to process a specific input. This occurs at the 'POST /api/experience/verification/verification-code' endpoint, leading to an event-loop stall that can render authentication, token issuance, SSO, and the administrative console unavailable.
Recommendations Update to version 1.41.0.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-62317
GHSA-QP7J-C3Q2-G739

Affected Products

Logto