6.1

CVE-2026-83589

Oauth-proxy: open redirect via /\ and /\t bypass in post-login redirect

A flaw was found in oauth-proxy. The application fails to properly validate the destination redirect parameter (`rd`) during post-login redirection. A remote attacker can exploit this vulnerability by enticing a user to follow a specially crafted link, resulting in the user being redirected to an arbitrary external website after authenticating. This open redirect can be leveraged to conduct phishing attacks or credential theft.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerRed Hat
≫
Produkt Red Hat OpenShift Container Platform 4.20
Default Statusaffected
Version 1790704224
Version < *
Status unaffected
HerstellerRed Hat
≫
Produkt Red Hat OpenShift Container Platform 4.21
Default Statusaffected
Version 1790706478
Version < *
Status unaffected
HerstellerRed Hat
≫
Produkt Red Hat OpenShift Container Platform 4.22
Default Statusaffected
Version 1790724885
Version < *
Status unaffected
HerstellerRed Hat
≫
Produkt Red Hat OpenShift Container Platform 4
Default Statusaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.19% 0.078
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
RedHat 6.1 2.8 2.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CWE-601 URL Redirection to Untrusted Site ('Open Redirect')

The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.

https://access.redhat.com/security/cve/CVE-2026-83589
https://bugzilla.redhat.com/show_bug.cgi?id=2518379
https://access.redhat.com/errata/RHSA-2026:74383
https://access.redhat.com/errata/RHSA-2026:74429
https://access.redhat.com/errata/RHSA-2026:74380