CVE-2026-83589

Summary

A flaw was found in oauth-proxy. The application fails to properly validate the destination redirect parameter (rd) during post-login redirection. A remote attacker can exploit this vulnerability by enticing a user to follow a specially crafted link, resulting in the user being redirected to an arbitrary external website after authenticating. This open redirect can be leveraged to conduct phishing attacks or credential theft.

Affected Software

VendorProductVersion RangeStatus

Weaknesses

  • CWE-601: URL Redirection to Untrusted Site ('Open Redirect')

Workarounds

Red Hat has not identified any known mitigations for this issue. Customers are advised to apply the available security update when released.

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References