{"id":"CVE-2026-91165","title":"Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux","summary":"Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.27.6, the response_mode=form_post SSO return path in warpgate-protocol-http/src/api/sso_provider_list.rs uses serde_json::to_string inside ReturnToSsoPost…","severity":"low","cvss":2.4,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N","cwe":["CWE-79"],"vendor":"warp-tech","product":"warpgate","affected":["warpgate < 0.27.6"],"published":"2026-09-21","updated":"2026-09-21","sourceUpdated":"2026-09-21T20:17:39.473","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-91165","references":[{"url":"https://github.com/warp-tech/warpgate/commit/e94425a08f501383a67316673749dcbd637c6ce3","label":"security-advisories@github.com"},{"url":"https://github.com/warp-tech/warpgate/releases/tag/v0.27.6","label":"security-advisories@github.com"},{"url":"https://github.com/warp-tech/warpgate/security/advisories/GHSA-vvpj-p7j8-4rv4","label":"security-advisories@github.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-21T19:26:11.810922Z"},"ingestedAt":"2026-09-21T19:51:58.863Z","epss":0.00228,"epssPercentile":0.13783,"slug":"CVE-2026-91165","body":"## Overview\n\nWarpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.27.6, the response_mode=form_post SSO return path in warpgate-protocol-http/src/api/sso_provider_list.rs uses serde_json::to_string inside ReturnToSsoPostResponse without neutralizing a script-closing sequence. The vulnerable value can enter the script block through the attacker-controlled next redirect parameter stored by warpgate-protocol-http/src/api/sso_provider_detail.rs or through IdP-derived error messages that make_redirect_url concatenates without URL encoding. The IdP-derived path is reachable when the attacker controls a configured identity provider, or when the attacker controls the email or username claim on an attacker-controlled account and the configured identity provider permits the required unvalidated claim format. A victim must complete the form_post SSO flow for the injected markup to be rendered. The Warpgate Content-Security-Policy blocks injected JavaScript and event handlers, so the demonstrated impact is content spoofing, a false login form, or a meta refresh rather than script execution. This issue is fixed in version 0.27.6.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":13,"depthScoreParts":{"impact":13.2,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}