CVE-2026-83589
6.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Summary
A flaw was found in oauth-proxy. The application fails to properly validate the destination redirect parameter (rd) during post-login redirection. A remote attacker can exploit this vulnerability by enticing a user to follow a specially crafted link, resulting in the user being redirected to an arbitrary external website after authenticating. This open redirect can be leveraged to conduct phishing attacks or credential theft.
Affected Software
| Vendor | Product | Version Range | Status |
|---|
Weaknesses
- CWE-601: URL Redirection to Untrusted Site ('Open Redirect')
Workarounds
Red Hat has not identified any known mitigations for this issue. Customers are advised to apply the available security update when released.
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: partial
References
- https://access.redhat.com/security/cve/CVE-2026-83589
- https://bugzilla.redhat.com/show_bug.cgi?id=2518379
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.