Octo STS Unauthenticated SSRF by abusing fields in OpenID Connect tokens in github.com/octo-sts/app
{ "review_status": "UNREVIEWED", "url": "https://pkg.go.dev/vuln/GO-2025-3779" }