CWE-601
CVEs classified under CWE-601, newest first.
160 CVEsRSS
CVE-2026-55403Low· 3.7datamodel-code-generator: Authorization / request headers leaked to cross-origin redirect target when fetching remote schemas
datamodel-code-generator: Authorization / request headers leaked to cross-origin redirect target when fetching remote schemas
CVE-2026-54588Critical· 9.6Poweradmin has Host Header Injection in OIDC redirect_uri, SAML ACS/SLO URL, and Logout Redirect Construction.
Poweradmin has Host Header Injection in OIDC redirect_uri, SAML ACS/SLO URL, and Logout Redirect Construction.
CVE-2026-54603High· 8.6OAuth2 is a Ruby wrapper for the OAuth 2.0 and 2.1 authorization frameworks, including OpenID Connect (OIDC)
OAuth2 is a Ruby wrapper for the OAuth 2.0 and 2.1 authorization frameworks, including OpenID Connect (OIDC). From 0.4.0 to 2.0.21, a protocol-relative redirect Location returned to OAuth2::Client#request overrides the request authority,…
GHSA-38hq-7x33-php4Medium· 4.7@backstage/plugin-auth-backend: Unauthenticated OAuth account takeover via `redirect_uri` allowlist bypass
@backstage/plugin-auth-backend: Unauthenticated OAuth account takeover via `redirect_uri` allowlist bypass
CVE-2026-53668Medium· 6.9React Router: Open redirect leading to XSS
React Router: Open redirect leading to XSS
CVE-2026-53669MediumReact Router: Open redirect via backslash in <Link> and useNavigate (CVE-2025-68470 bypass)
React Router: Open redirect via backslash in <Link> and useNavigate (CVE-2025-68470 bypass)
CVE-2026-60685Medium· 6.1Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations)
Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with net…
CVE-2026-61181High· 7.6Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Product Quality Management)
Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Product Quality Management). The supported version that is affected is 6.2.4. Easily exploitable vulnerability allows…
CVE-2026-60642High· 7.6Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server)
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated …
CVE-2026-60641High· 7.6Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server)
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated …
CVE-2026-47026High· 7.4Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: OpenSearch Dashboards)
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: OpenSearch Dashboards). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated atta…
CVE-2026-47015High· 7.1Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology)
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology). The supported version that is affected is 8.62. Easily exploitable vulnerability allows unauthenticated attacker with…
CVE-2026-63768Medium· 4.3cal.diy through 6.2.0 contains an open redirect vulnerability in the conferencing OAuth callback endpoint that allows attackers to redirect users to arbitrary URLs by crafting malicious state parameters
cal.diy through 6.2.0 contains an open redirect vulnerability in the conferencing OAuth callback endpoint that allows attackers to redirect users to arbitrary URLs by crafting malicious state parameters. Attackers can exploit the unsigne…
CVE-2026-59730Low@astrojs/node: Backslash-prefixed paths not recognized as internal by trailing-slash redirect
@astrojs/node: Backslash-prefixed paths not recognized as internal by trailing-slash redirect
CVE-2026-15093Medium· 4.3IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to redirect users to malicious websites due to improper validation of user-supplied URLs.
IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to redirect users to malicious websites due to improper validation of user-supplied URLs.
CVE-2026-44745High· 8.1SAP Approuter does not properly validate incoming request headers during the OAuth2 login flow under certain configurations
SAP Approuter does not properly validate incoming request headers during the OAuth2 login flow under certain configurations. This allows an unauthenticated remote attacker to craft a malicious link which, when clicked by a victim, could …
CVE-2026-48000Medium· 6.1Adobe Commerce is affected by an Improper Redirect (Open Redirect) vulnerability that could result in a Security feature bypass
Adobe Commerce is affected by an Improper Redirect (Open Redirect) vulnerability that could result in a Security feature bypass. An attacker could construct a malicious URL that redirects a victim to an attacker-controlled site. Exploita…
CVE-2026-55806NoneURL Redirection to Untrusted Site ('Open Redirect') vulnerability in Drupal Drupal core allows Content Spoofing
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Drupal Drupal core allows Content Spoofing. This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 …
CVE-2026-55461Medium· 6.1Snipe-IT is an IT asset/license management system
Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the user edit flow stores url()->previous() from the attacker-controlled Referer header into Laravel’s intended URL session value and later uses redirect()->intended(...)…
CVE-2026-55252MediumOpenRun: Redirect URL validation bypass using //host paths leads to Open Redirect
OpenRun: Redirect URL validation bypass using //host paths leads to Open Redirect
GHSA-86j7-9j95-vpqjHigh· 7.7Better Auth has stored XSS in the auth-server origin via javascript: redirect_uri in oidc-provider and mcp
Better Auth has stored XSS in the auth-server origin via javascript: redirect_uri in oidc-provider and mcp
CVE-2026-55431High· 7.7Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps
Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps
CVE-2026-53935Medium· 6.9CiliumLocalRedirectPolicy addressMatcher allows cross-namespace service traffic hijacking and can break service translation
CiliumLocalRedirectPolicy addressMatcher allows cross-namespace service traffic hijacking and can break service translation
CVE-2026-41106Critical· 9.3Microsoft 365 Copilot Elevation of Privilege Vulnerability
Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.
GHSA-9c3v-684m-579cMedium· 6.5OpenClaw MCP SSE redirects could forward Authorization headers
OpenClaw MCP SSE redirects could forward Authorization headers
CVE-2026-47070MediumHackney: Cross-origin Redirect Leaks Authorization, Cookie, and Request Body
Hackney: Cross-origin Redirect Leaks Authorization, Cookie, and Request Body
CVE-2026-53523Medium· 6.8Nezha Monitoring: OAuth2 Redirect URL — Host Header Injection
Nezha Monitoring: OAuth2 Redirect URL — Host Header Injection
CVE-2026-52802Medium· 5.4Gogs has an Open Redirect via redirect_to
Gogs has an Open Redirect via redirect_to
GHSA-w2j7-f3c6-g8cwMedium· 4.7Flask-Security has an Open Redirect issue
Flask-Security has an Open Redirect issue
CVE-2026-54276Medium· 6.1AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, DigestAuthMiddleware can send an authentication response after following a cross-origin redirect. This likely requires an open redirect vuln…