A vulnerability marked as critical has been reported in Eclipse PIA up to 0.5.x. This issue affects some unknown processing of the file /v1/upload/sbom of the component OIDC Discovery. The manipulation of the argument iss leads to server-side request forgery.
This vulnerability is listed as CVE-2026-18353. The attack may be initiated remotely. There is no available exploit.
It is suggested to upgrade the affected component.