Loading market data...
← Back to CVE feed

CVE-2026-83589

MEDIUM CVSS 6.1 View on NVD ↗

Description

A flaw was found in oauth-proxy. The application fails to properly validate the destination redirect parameter (`rd`) during post-login redirection. A remote attacker can exploit this vulnerability by enticing a user to follow a specially crafted link, resulting in the user being redirected to an arbitrary external website after authenticating. This open redirect can be leveraged to conduct phishing attacks or credential theft.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Published: Oct 01, 2026 10:17 UTC Modified: Oct 01, 2026 17:17 UTC