CVE-2026-103957 - Server-side request forgery in the OAuth2 discovery handling in Loom for AWS
CVE ID :CVE-2026-103957 Published : Oct. 2, 2026, 7:06 p.m. | 14 minutes ago Description :Server-side request forgery in the OAuth2 discovery handling in Loom for AWS before 1.7.0 might allow an authenticated remote user to obtain the access token of another user of the deployment and to...