Octo STS Unauthenticated SSRF by abusing fields in OpenID Connect tokens in github.com/octo-sts/app
{ "url": "https://pkg.go.dev/vuln/GO-2025-3779", "review_status": "UNREVIEWED" }