VulnSea

CWE-601

CVEs classified under CWE-601, newest first.

159 CVEsRSS

CVE-2026-82464Medium· 6.1
4w ago

pac4j-core before 6.5.6 contains an open redirect vulnerability in DefaultLogoutLogic.perform() that accepts backslash-prefixed logout redirect targets matching logoutUrlPattern

pac4j-core before 6.5.6 contains an open redirect vulnerability in DefaultLogoutLogic.perform() that accepts backslash-prefixed logout redirect targets matching logoutUrlPattern. Attackers can craft logout links with backslash-prefixed e…

▾ SunlitEPSS 0.35%via NVD
CVE-2026-81342Medium· 4.7
4w ago

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.43 does not validate a redirect parameter supplied during user registration before using it, allowing unauthenticated attackers to redirect users to arbitrary external URLs.

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.43 does not validate a redirect parameter supplied during user registration before using it, allowing unauthenticated attackers to redirect users to arbitrary external URLs.

▾ SunlitEPSS 0.29%via NVD
CVE-2026-82274Medium· 4.7PoC
1mo ago

Twenty through 2.35.0 contains an open redirect vulnerability in the OAuthPropagatorController.propagateOAuthCallback endpoint that treats the state query parameter as a redirect URL

Twenty through 2.35.0 contains an open redirect vulnerability in the OAuthPropagatorController.propagateOAuthCallback endpoint that treats the state query parameter as a redirect URL. Attackers can craft malicious requests to redirect us…

▾ Twilighttwentyhq · twentyEPSS 0.28%via NVD
CVE-2026-55834Medium· 4.3
1mo ago

Pocket ID is an OIDC provider that allows users to authenticate with their passkeys to services

Pocket ID is an OIDC provider that allows users to authenticate with their passkeys to services. From 2.6.0 until 2.9.0, frontend/src/routes/authorize/+page.ts reads the redirect_uri query parameter and frontend/src/routes/authorize/+pag…

▾ Sunlitpocket-id · github.com/pocket-id/pocket-id/backendEPSS 0.37%via NVD
CVE-2026-47883Medium· 6.1PoC
1mo ago

UrlHandlerFilter can be vulnerable to an open redirect when configured with very broadly matching patterns

UrlHandlerFilter can be vulnerable to an open redirect when configured with very broadly matching patterns. The issue applies to the filter variants in both Spring MVC and Spring WebFlux. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6…

▾ Twilightvmware · spring_frameworkEPSS 0.26%via NVD
CVE-2026-47887Medium· 6.1
1mo ago

A Spring MVC application that uses UrlFileNameViewController that is mapped with an end-of-path, and does not have a configured prefix is vulnerable to an open redirect. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spri…

A Spring MVC application that uses UrlFileNameViewController that is mapped with an end-of-path, and does not have a configured prefix is vulnerable to an open redirect. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spri…

▾ Sunlitvmware · spring_frameworkEPSS 0.24%via NVD
CVE-2026-42350Low
1mo ago

Kargo has Open Redirect in UI OIDC Login Flow via redirectTo Query Parameter

Kargo has Open Redirect in UI OIDC Login Flow via redirectTo Query Parameter

▾ Sunlitakuity · github.com/akuity/kargoEPSS 0.41%via GHSA
CVE-2026-81029High· 8.1
1mo ago

OpenMetadata accepts a caller-supplied post-authentication redirect target and appends the issued token to it

OpenMetadata accepts a caller-supplied post-authentication redirect target and appends the issued token to it. SamlLoginServlet reads the callback request parameter and stores it in the HTTP session without comparing it against any confi…

▾ TwilightEPSS 0.55%via NVD
CVE-2026-81036High· 8.1
1mo ago

Stalwart Mail Server does not compare an OAuth redirect target against any registered destination in its default configuration

Stalwart Mail Server does not compare an OAuth redirect target against any registered destination in its default configuration. The validation routine in crates/http/src/auth/oauth/registration.rs returns success immediately when the cli…

▾ TwilightEPSS 0.39%via NVD
CVE-2026-79786High· 7.1
1mo ago

Coroot's unauthenticated MCP OAuth dynamic client registration endpoint accepts any syntactically valid redirect URI without validation, allowing attackers to register clients pointing to attacker-controlled hosts

Coroot's unauthenticated MCP OAuth dynamic client registration endpoint accepts any syntactically valid redirect URI without validation, allowing attackers to register clients pointing to attacker-controlled hosts. Attackers can send aut…

▾ TwilightEPSS 0.27%via NVD
CVE-2026-49996Low· 3.7
1mo ago

SecureDrop Client is a desktop app for journalists to securely communicate with sources and handle submissions on the SecureDrop Workstation

SecureDrop Client is a desktop app for journalists to securely communicate with sources and handle submissions on the SecureDrop Workstation. Prior to version 1.3.1, a malicious SecureDrop Server could bypass securedrop-proxy's origin li…

▾ SunlitEPSS 0.31%via NVD
CVE-2026-53586Medium· 6.5
1mo ago

libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application

libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Prior to 1.8.6 and 1.9.5, the built-in HTTP transport in src/libgi…

▾ SunlitEPSS 0.48%via NVD
CVE-2026-71428Critical· 9.3
1mo ago

The unstructured library provides open-source components for ingesting and pre-processing images and text documents, such as PDFs, HTML, Word docs, and many more

The unstructured library provides open-source components for ingesting and pre-processing images and text documents, such as PDFs, HTML, Word docs, and many more. From 0.4.7 until 0.24.0, the url argument of partition, partition_html, an…

▾ Midnightunstructured · unstructuredEPSS 0.44%via NVD
CVE-2026-54770Medium· 6.1
1mo ago

WebOb provides objects for HTTP requests and responses

WebOb provides objects for HTTP requests and responses. Prior to 1.8.11, Response._make_location_absolute() in src/webob/response.py checks a Location value for a URI scheme or leading double slash before urllib.parse.urljoin() strips le…

▾ SunlitRed Hat · Red Hat OpenStack Platform 16.2EPSS 0.38%via NVD
CVE-2026-53654None
1mo ago

Grav is a file-based Web platform

Grav is a file-based Web platform. Prior to 3.8.5, the Login plugin twofa_cancel task accepts a client-controlled _redirect field without a nonce and allows an unauthenticated request to set an external http, https, or protocol-relative …

▾ SunlitEPSS 0.53%via NVD
CVE-2026-55087Medium· 6.1PoC
1mo ago

Etherpad is a real-time collaborative editor

Etherpad is a real-time collaborative editor. From 2.1.0 until 3.1.0, Etherpad uses the attacker-controlled x-proxy-path request header in src/node/hooks/express/admin.ts when substituting paths into HTML, JavaScript, and CSS under /admi…

▾ Twilightep_etherpad-lite · ep_etherpad-liteEPSS 0.58%via NVD
CVE-2026-75833Medium· 4.2
1mo ago

The Grav API plugin (getgrav/grav-plugin-api, bundled with Grav 2.0's admin-next/API stack) before version 1.0.14 contains an open redirect weakness in SsoController::sanitizeReturnTo()

The Grav API plugin (getgrav/grav-plugin-api, bundled with Grav 2.0's admin-next/API stack) before version 1.0.14 contains an open redirect weakness in SsoController::sanitizeReturnTo(). The function rejects a literal '//' prefix but doe…

▾ SunlitEPSS 0.22%via NVD
CVE-2026-70958Critical· 9.6
1mo ago

Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration)

Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows una…

▾ MidnightEPSS 0.42%via NVD
CVE-2025-71405Medium
1mo ago

chi versions before v5.2.2 contain an open redirect vulnerability in the RedirectSlashes middleware function that uses the Host header to construct redirect URLs

chi versions before v5.2.2 contain an open redirect vulnerability in the RedirectSlashes middleware function that uses the Host header to construct redirect URLs. Attackers can manipulate the Host header to redirect users to arbitrary ho…

▾ Sunlitgo-chi · github.com/go-chi/chi/v5EPSS 0.39%via NVD
CVE-2026-49826Low
1mo ago

Concourse is a container-based automation system written in Go

Concourse is a container-based automation system written in Go. Prior to version 8.2.3, an attacker is able to craft and send a user a URL that will redirect the user from the Concourse web server to any other site. This could be used in…

▾ Sunlitconcourse · github.com/concourse/concourseEPSS 0.53%via NVD
CVE-2026-73563Medium· 4.7
1mo ago

Backstage is an open framework for building developer portals

Backstage is an open framework for building developer portals. Prior to 0.29.2, the experimental dynamic client registration and client ID metadata document features in the @backstage/plugin-auth-backend use full-string matcher.isMatch g…

▾ SunlitEPSS 0.28%via NVD
CVE-2026-46688Medium· 6.9
1mo ago

The Meeting Room Booking System (MRBS) is a PHP-based application for booking meeting rooms

The Meeting Room Booking System (MRBS) is a PHP-based application for booking meeting rooms. Prior to version 1.12.2, an unauthenticated request can be made to redirect the user to a query-specified location. This allows an attacker to c…

▾ Sunlitmeeting-room-booking-system · mrbs-codeEPSS 0.42%via NVD
CVE-2026-49820Medium· 4.7
1mo ago

Probo is a self-hostable governance, risk, and compliance (GRC) platform built for engineering and security teams

Probo is a self-hostable governance, risk, and compliance (GRC) platform built for engineering and security teams. Probo's `saferedirect` package validates redirect URLs used across authentication flows (OIDC, SAML, session transfer, OAu…

▾ Sunlitprobo · go.probo.inc/proboEPSS 0.42%via NVD
CVE-2026-58230High· 7.0
1mo ago

SAP Approuter does not sufficiently validate certain token content under specific configurations

SAP Approuter does not sufficiently validate certain token content under specific configurations. An unauthenticated attacker could send a specially crafted token to cause sensitive credential material to be sent to an attacker-controlle…

▾ Twilightsap · approuterEPSS 0.31%via NVD
CVE-2026-59717Medium· 4.3
1mo ago

Home Assistant is open source home automation software focused on local control and privacy

Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.6.1, the Android Companion app is vulnerable to an open redirect. The app passes the URL fragment from a homeassistant://invite de…

▾ SunlitEPSS 0.38%via NVD
CVE-2025-71403High· 7.1
1mo ago

better-auth versions before 1.1.20 contain a bypass vulnerability in trustedOrigins validation logic affecting absolute URLs and wildcard domains

better-auth versions before 1.1.20 contain a bypass vulnerability in trustedOrigins validation logic affecting absolute URLs and wildcard domains. Attackers can construct malicious callbackURL parameters that pass origin checks and trigg…

▾ TwilightEPSS 0.34%via NVD
CVE-2026-67350Medium· 4.3
1mo ago

Serendipity before 2.6.1 contains an open redirect vulnerability in exit.php that allows unauthenticated attackers to redirect users to arbitrary external sites by supplying a malicious Base64-encoded url parameter when the Track Exits p…

Serendipity before 2.6.1 contains an open redirect vulnerability in exit.php that allows unauthenticated attackers to redirect users to arbitrary external sites by supplying a malicious Base64-encoded url parameter when the Track Exits p…

▾ SunlitEPSS 0.35%via NVD
CVE-2026-53573Medium
1mo ago

GeoNetwork is a catalog application to manage spatially referenced resources

GeoNetwork is a catalog application to manage spatially referenced resources. From 3.12.0 until 4.2.16 and 4.4.11, unsafe redirect validation in GeonetworkOAuth2LoginAuthenticationFilter and KeycloakAuthenticationProcessingFilter permits…

▾ Sunlitgeonetwork-opensource · org.geonetwork-opensource:geonetworkEPSS 0.65%via NVD
CVE-2026-66414Medium· 6.1PoC
1mo ago

Leantime Open Redirect in Login Controller via redirectUrl Parameter

Leantime 3.6.2 contains an open redirect vulnerability in the Login controller that allows unauthenticated attackers to redirect authenticated users to arbitrary external sites by manipulating the redirectUrl POST parameter. Attackers ca…

▾ TwilightLeantime · LeantimeEPSS 0.34%via CVEORG
CVE-2026-55403Low· 3.7
2mo ago

datamodel-code-generator: Authorization / request headers leaked to cross-origin redirect target when fetching remote schemas

datamodel-code-generator: Authorization / request headers leaked to cross-origin redirect target when fetching remote schemas

▾ Sunlitdatamodel-code-generator · datamodel-code-generatorEPSS 0.34%via OSV
CWE-601 vulnerabilities (CVEs) — page 3 · VulnSea