VulnSea

CWE-601

CVEs classified under CWE-601, newest first.

160 CVEsRSS

CVE-2026-55403Low· 3.7
2mo ago

datamodel-code-generator: Authorization / request headers leaked to cross-origin redirect target when fetching remote schemas

datamodel-code-generator: Authorization / request headers leaked to cross-origin redirect target when fetching remote schemas

▾ Sunlitdatamodel-code-generator · datamodel-code-generatorEPSS 0.34%via OSV
CVE-2026-54588Critical· 9.6
2mo ago

Poweradmin has Host Header Injection in OIDC redirect_uri, SAML ACS/SLO URL, and Logout Redirect Construction.

Poweradmin has Host Header Injection in OIDC redirect_uri, SAML ACS/SLO URL, and Logout Redirect Construction.

▾ Midnightpoweradmin · poweradmin/poweradminEPSS 0.54%via GHSA
CVE-2026-54603High· 8.6
2mo ago

OAuth2 is a Ruby wrapper for the OAuth 2.0 and 2.1 authorization frameworks, including OpenID Connect (OIDC)

OAuth2 is a Ruby wrapper for the OAuth 2.0 and 2.1 authorization frameworks, including OpenID Connect (OIDC). From 0.4.0 to 2.0.21, a protocol-relative redirect Location returned to OAuth2::Client#request overrides the request authority,…

▾ Twilightoauth2 · oauth2EPSS 0.59%via NVD
GHSA-38hq-7x33-php4Medium· 4.7
2mo ago

@backstage/plugin-auth-backend: Unauthenticated OAuth account takeover via `redirect_uri` allowlist bypass

@backstage/plugin-auth-backend: Unauthenticated OAuth account takeover via `redirect_uri` allowlist bypass

▾ Sunlitbackstage · @backstage/plugin-auth-backendvia GHSA
CVE-2026-53668Medium· 6.9
2mo ago

React Router: Open redirect leading to XSS

React Router: Open redirect leading to XSS

▾ Sunlitreact-router · react-routerEPSS 0.34%via GHSA
CVE-2026-53669Medium
2mo ago

React Router: Open redirect via backslash in <Link> and useNavigate (CVE-2025-68470 bypass)

React Router: Open redirect via backslash in <Link> and useNavigate (CVE-2025-68470 bypass)

▾ Sunlitreact-router · react-routerEPSS 0.32%via GHSA
CVE-2026-60685Medium· 6.1
2mo ago

Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations)

Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with net…

▾ Sunlitoracle · e-business_suiteEPSS 0.13%via NVD
CVE-2026-61181High· 7.6
2mo ago

Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Product Quality Management)

Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Product Quality Management). The supported version that is affected is 6.2.4. Easily exploitable vulnerability allows…

▾ Twilightoracle · agile_product_lifecycle_management_for_processEPSS 0.27%via NVD
CVE-2026-60642High· 7.6
2mo ago

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server)

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated …

▾ Twilightoracle · webcenter_contentEPSS 0.15%via NVD
CVE-2026-60641High· 7.6
2mo ago

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server)

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated …

▾ Twilightoracle · webcenter_contentEPSS 0.30%via NVD
CVE-2026-47026High· 7.4
2mo ago

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: OpenSearch Dashboards)

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: OpenSearch Dashboards). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated atta…

▾ Twilightoracle · peoplesoft_enterprise_peopletoolsEPSS 0.37%via NVD
CVE-2026-47015High· 7.1
2mo ago

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology)

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology). The supported version that is affected is 8.62. Easily exploitable vulnerability allows unauthenticated attacker with…

▾ Twilightoracle · peoplesoft_enterprise_peopletoolsEPSS 0.24%via NVD
CVE-2026-63768Medium· 4.3
2mo ago

cal.diy through 6.2.0 contains an open redirect vulnerability in the conferencing OAuth callback endpoint that allows attackers to redirect users to arbitrary URLs by crafting malicious state parameters

cal.diy through 6.2.0 contains an open redirect vulnerability in the conferencing OAuth callback endpoint that allows attackers to redirect users to arbitrary URLs by crafting malicious state parameters. Attackers can exploit the unsigne…

▾ Sunlitcalcom · cal.diyEPSS 0.34%via NVD
CVE-2026-59730Low
2mo ago

@astrojs/node: Backslash-prefixed paths not recognized as internal by trailing-slash redirect

@astrojs/node: Backslash-prefixed paths not recognized as internal by trailing-slash redirect

▾ Sunlitastrojs · @astrojs/nodeEPSS 0.46%via GHSA
CVE-2026-15093Medium· 4.3
2mo ago

IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to redirect users to malicious websites due to improper validation of user-supplied URLs.

IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to redirect users to malicious websites due to improper validation of user-supplied URLs.

▾ SunlitEPSS 0.36%via NVD
CVE-2026-44745High· 8.1
2mo ago

SAP Approuter does not properly validate incoming request headers during the OAuth2 login flow under certain configurations

SAP Approuter does not properly validate incoming request headers during the OAuth2 login flow under certain configurations. This allows an unauthenticated remote attacker to craft a malicious link which, when clicked by a victim, could …

▾ Twilightsap · approuterEPSS 0.47%via NVD
CVE-2026-48000Medium· 6.1
2mo ago

Adobe Commerce is affected by an Improper Redirect (Open Redirect) vulnerability that could result in a Security feature bypass

Adobe Commerce is affected by an Improper Redirect (Open Redirect) vulnerability that could result in a Security feature bypass. An attacker could construct a malicious URL that redirects a victim to an attacker-controlled site. Exploita…

▾ Sunlitadobe · commerceEPSS 0.46%via NVD
CVE-2026-55806None
2mo ago

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Drupal Drupal core allows Content Spoofing

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Drupal Drupal core allows Content Spoofing. This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 …

▾ SunlitEPSS 0.34%via NVD
CVE-2026-55461Medium· 6.1
2mo ago

Snipe-IT is an IT asset/license management system

Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the user edit flow stores url()->previous() from the attacker-controlled Referer header into Laravel’s intended URL session value and later uses redirect()->intended(...)…

▾ SunlitEPSS 0.31%via NVD
CVE-2026-55252Medium
2mo ago

OpenRun: Redirect URL validation bypass using  //host  paths leads to Open Redirect

OpenRun: Redirect URL validation bypass using  //host  paths leads to Open Redirect

▾ Sunlitopenrundev · github.com/openrundev/openrunvia GHSA
GHSA-86j7-9j95-vpqjHigh· 7.7
2mo ago

Better Auth has stored XSS in the auth-server origin via javascript: redirect_uri in oidc-provider and mcp

Better Auth has stored XSS in the auth-server origin via javascript: redirect_uri in oidc-provider and mcp

▾ Twilightbetter-auth · better-authvia GHSA
CVE-2026-55431High· 7.7
2mo ago

Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps

Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps

▾ Twilightcoder · github.com/coder/coder/v2EPSS 0.34%via GHSA
CVE-2026-53935Medium· 6.9
2mo ago

CiliumLocalRedirectPolicy addressMatcher allows cross-namespace service traffic hijacking and can break service translation

CiliumLocalRedirectPolicy addressMatcher allows cross-namespace service traffic hijacking and can break service translation

▾ Sunlitcilium · github.com/cilium/ciliumEPSS 0.34%via GHSA
CVE-2026-41106Critical· 9.3
2mo ago

Microsoft 365 Copilot Elevation of Privilege Vulnerability

Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.

▾ MidnightMicrosoft · Microsoft 365 CopilotEPSS 0.72%via CVEORG
GHSA-9c3v-684m-579cMedium· 6.5
2mo ago

OpenClaw MCP SSE redirects could forward Authorization headers

OpenClaw MCP SSE redirects could forward Authorization headers

▾ Sunlitopenclaw · openclawvia GHSA
CVE-2026-47070Medium
3mo ago

Hackney: Cross-origin Redirect Leaks Authorization, Cookie, and Request Body

Hackney: Cross-origin Redirect Leaks Authorization, Cookie, and Request Body

▾ Sunlithackney · hackneyEPSS 0.35%via GHSA
CVE-2026-53523Medium· 6.8
3mo ago

Nezha Monitoring: OAuth2 Redirect URL — Host Header Injection

Nezha Monitoring: OAuth2 Redirect URL — Host Header Injection

▾ Sunlitnezhahq · github.com/nezhahq/nezhaEPSS 0.32%via GHSA
CVE-2026-52802Medium· 5.4
3mo ago

Gogs has an Open Redirect via redirect_to

Gogs has an Open Redirect via redirect_to

▾ Sunlitgogs · gogs.io/gogsEPSS 0.55%via GHSA
GHSA-w2j7-f3c6-g8cwMedium· 4.7
3mo ago

Flask-Security has an Open Redirect issue

Flask-Security has an Open Redirect issue

▾ SunlitFlask-Security · Flask-Securityvia GHSA
CVE-2026-54276Medium· 6.1
3mo ago

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, DigestAuthMiddleware can send an authentication response after following a cross-origin redirect. This likely requires an open redirect vuln…

▾ Sunlitaiohttp · aiohttpEPSS 0.31%via NVD
CWE-601 vulnerabilities (CVEs) — page 4 · VulnSea