The 'clientId' parameter from incoming HTTP requests is directly concatenated into OAuth2 server log warning messages without sanitizing…
apache·CWE-93·Published 2026-06-12