{"id":"CVE-2026-49826","title":"Concourse is a container-based automation system written in Go","summary":"Concourse is a container-based automation system written in Go. Prior to version 8.2.3, an attacker is able to craft and send a user a URL that will redirect the user from the Concourse web server to any other site. This could be used in…","severity":"low","cwe":["CWE-601"],"vendor":"concourse","product":"github.com/concourse/concourse","affected":["github.com/concourse/concourse < 1.6.1-0.20260526150512-ac60be5f0435"],"patched":["github.com/concourse/concourse 1.6.1-0.20260526150512-ac60be5f0435"],"published":"2026-08-14","updated":"2026-09-18","sourceUpdated":"2026-09-18T20:05:53.723","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-49826","references":[{"url":"https://github.com/concourse/concourse/commit/ac60be5f0435b6592f5a4fcc089050d72ad2452c","label":"security-advisories@github.com"},{"url":"https://github.com/concourse/concourse/releases/tag/v8.2.3","label":"security-advisories@github.com"},{"url":"https://github.com/concourse/concourse/security/advisories/GHSA-8w27-c4vc-88q9","label":"security-advisories@github.com"},{"url":"https://github.com/advisories/GHSA-8w27-c4vc-88q9"}],"tags":["nvd","ghsa","go"],"epss":0.00526,"epssPercentile":0.42082,"ecosystem":"go","ingestedAt":"2026-07-01T19:15:59.899Z","slug":"CVE-2026-49826","body":"## Overview\n\nConcourse is a container-based automation system written in Go. Prior to version 8.2.3, an attacker is able to craft and send a user a URL that will redirect the user from the Concourse web server to any other site. This could be used in a phishing attack to steal user's credentials. This has been fixed in 8.2.3. No known workarounds are available.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-49826)\n\nAffected packages:\n\n- `github.com/concourse/concourse < 1.6.1-0.20260526150512-ac60be5f0435`\n\nPatched in:\n\n- `github.com/concourse/concourse 1.6.1-0.20260526150512-ac60be5f0435`\n\nSource: https://github.com/advisories/GHSA-8w27-c4vc-88q9","depth":"sunlit","depthScore":14,"depthScoreParts":{"impact":13.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}