Description
A flaw was found in oauth-proxy. The application fails to properly validate the destination redirect parameter (`rd`) during post-login redirection. A remote attacker can exploit this vulnerability by enticing a user to follow a specially crafted link, resulting in the user being redirected to an arbitrary external website after authenticating. This open redirect can be leveraged to conduct phishing attacks or credential theft.
Published: 2026-10-01
Score: 6.1 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

Vendor Workaround

Red Hat has not identified any known mitigations for this issue. Customers are advised to apply the available security update when released.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 09:30:00 +0000

Type Values Removed Values Added
Description No description is available for this CVE. A flaw was found in oauth-proxy. The application fails to properly validate the destination redirect parameter (`rd`) during post-login redirection. A remote attacker can exploit this vulnerability by enticing a user to follow a specially crafted link, resulting in the user being redirected to an arbitrary external website after authenticating. This open redirect can be leveraged to conduct phishing attacks or credential theft.
Title oauth-proxy: Open Redirect via /\ and /\t Bypass in Post-Login Redirect Oauth-proxy: open redirect via /\ and /\t bypass in post-login redirect
First Time appeared Redhat
Redhat openshift
CPEs cpe:/a:redhat:openshift:4
Vendors & Products Redhat
Redhat openshift
References

Fri, 04 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Oauth2 Proxy Project
Oauth2 Proxy Project oauth2 Proxy
Vendors & Products Oauth2 Proxy Project
Oauth2 Proxy Project oauth2 Proxy

Wed, 02 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Description No description is available for this CVE.
Title oauth-proxy: Open Redirect via /\ and /\t Bypass in Post-Login Redirect
Weaknesses CWE-601
References
Metrics threat_severity

None

cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

threat_severity

Important


Subscriptions

Oauth2 Proxy Project Oauth2 Proxy
Redhat Openshift
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-10-01T09:17:43.584Z

Reserved: 2026-08-31T19:18:43.003Z

Link: CVE-2026-83589

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-01T10:17:17.217

Modified: 2026-10-01T12:41:25.413

Link: CVE-2026-83589

cve-icon Redhat

Severity : Important

Publid Date: 2026-08-31T20:00:00Z

Links: CVE-2026-83589 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T11:45:07Z

Weaknesses
  • CWE-601

    URL Redirection to Untrusted Site ('Open Redirect')