github.com/octo-sts/app
Go2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting github.com/octo-sts/apppage 1 of 1
- CVE-2024-34079LOWCVSS 3.7EG 3.7✓ Fixed in 0.1.02024-05-14
octo-sts is a GitHub App that acts like a Security Token Service (STS) for the Github API. This vulnerability can spike the resource utilization of the STS service, and combined with a significant traffic volume could potentially lead to a…
- CVE-2025-52477HIGHCVSS 8.6EG 8.6✓ Fixed in 0.5.32025-06-26
Octo-STS is a GitHub App that acts like a Security Token Service (STS) for the GitHub API. Octo-STS versions before v0.5.3 are vulnerable to unauthenticated SSRF by abusing fields in OpenID Connect tokens. Malicious tokens were shown to tr…
Check whether github.com/octo-sts/app is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for github.com/octo-sts/app CVEs against the assets you own.
Start Free Scan →