{"id":"CVE-2026-85676","title":"Dub contains an open redirect vulnerability in the redir_url query parameter that is accepted on every short link without validation or domain allowlist enforcement","summary":"Dub contains an open redirect vulnerability in the redir_url query parameter that is accepted on every short link without validation or domain allowlist enforcement. Attackers can append the redir_url parameter to any short link to redir…","severity":"medium","cvss":4.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N","cwe":["CWE-601"],"vendor":"dubinc","product":"dub","affected":["dub <= 73415cf5e6be13ce9adb7ba5e97474307db34a17"],"published":"2026-09-04","updated":"2026-09-14","sourceUpdated":"2026-09-14T20:16:59.527","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-85676","references":[{"url":"https://github.com/dubinc/dub","label":"disclosure@vulncheck.com"},{"url":"https://github.com/dubinc/dub/blob/73415cf5e6be13ce9adb7ba5e97474307db34a17/apps/web/lib/middleware/utils/get-final-url.ts","label":"disclosure@vulncheck.com"},{"url":"https://github.com/dubinc/dub/issues/4337","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/dub-open-redirect-via-unrestricted-redir-url-parameter","label":"disclosure@vulncheck.com"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-85676.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-85676"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-85676"}],"tags":["nvd","cve.org","csaf","vex","red-hat"],"epss":0.00242,"epssPercentile":0.15652,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-14T19:20:39.606590Z"},"ingestedAt":"2026-09-14T20:14:21.165Z","slug":"CVE-2026-85676","body":"## Overview\n\nDub contains an open redirect vulnerability in the redir_url query parameter that is accepted on every short link without validation or domain allowlist enforcement. Attackers can append the redir_url parameter to any short link to redirect visitors to arbitrary external URLs through the trusted Dub domain, bypassing destination blacklists and potentially enabling phishing attacks with link cloaking enabled.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Vendor advisories\n\n- **Red Hat VEX** · updated 2026-09-15 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-85676.json)","depth":"sunlit","depthScore":24,"depthScoreParts":{"impact":23.7,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}