CVE-2026-83589Medium· 6.1▾ SunlitA flaw was found in oauth-proxy. The application fails to properly validate the destination redirect parameter (`rd`) during post-login redirection. A remote attacker can exploit this vulnerability by enticing a user to follow a speciall…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 33.6 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
A flaw was found in oauth-proxy. The application fails to properly validate the destination redirect parameter (rd) during post-login redirection. A remote attacker can exploit this vulnerability by enticing a user to follow a specially crafted link, resulting in the user being redirected to an arbitrary external website after authenticating. This open redirect can be leveraged to conduct phishing attacks or credential theft.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-53683Medium· 4.3Freeipa: idm: idm/freeipa web ui - client-side open redirect in reset_password.html
CVE-2026-49332High· 8.5A flaw was found in openshift/oauth-proxy
CVE-2026-54770Medium· 6.1WebOb provides objects for HTTP requests and responses
CVE-2026-53669Medium· 5.4react-router: React Router: Open Redirect vulnerability via backslashes in navigation components (CVE-2026-53669)
CVE-2025-50181Medium· 5.3urllib3: urllib3 redirects are not disabled when retries are disabled on PoolManager instantiation (CVE-2025-50181)
CVE-2025-50182Medium· 5.3urllib3: urllib3 does not control redirects in browsers and Node.js (CVE-2025-50182)