CWE-601

Low likelihood

URL Redirection to Untrusted Site ('Open Redirect')

Parent: CWE-610 - Externally Controlled Reference to a Resource in Another Sphere

The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.

1,628 vulnerabilities with CWE-601
CVE-2026-28301 MEDIUM
SolarWinds Observability Self-Hosted Open Redirect Vulnerability
CVSS 4.8
CVE-2026-47347 MEDIUM
TYPO3 CMS - Open Redirect in Core Utilities
CVE-2026-41844 MEDIUM
Spring Framework Open Redirect in Spring MVC and WebFlux
CVSS 4.2
CVE-2026-11502 LOW
JeecgBoot Third-Party Login ThirdLoginController.java HttpServletResponse.sendRedirect redirect
CVSS 3.1
CVE-2026-11477 MEDIUM
hs-web hsweb-framework OAuth2 Client OAuth2Client.java OAuth2Client redirect
CVSS 4.3
CVE-2026-21826 MEDIUM
HCL Digital Experience and HCL Digital Experience Compose could be susceptible to Host header injection
CVSS 6.1
CVE-2026-10861 MEDIUM
MISP post-login open redirect via pre_login_requested_url
CVSS 6.1
CVE-2026-10856 MEDIUM
Open redirect in MISP dashboard button widget URL handling
CVSS 6.1
CVE-2026-43924 MEDIUM
FOSSBilling <0.8.0 Redirect Module - Open Redirect
CVE-2026-41569 MEDIUM
authentik Before 2026.2.3 - WS-Federation wreply Origin Bypass
CVSS 6.1
CVE-2026-40181 MEDIUM
React Router's same-origin redirect with path starting // causes open redirect via protocol-relative URL reinterpretation
CVSS 6.1
CVE-2026-45278 LOW
Nextcloud user_oidc 6.1.0-8.2.1 - Open Redirect via Login Flow
CVSS 3.3
CVE-2026-40961 HIGH
Apache Airflow: Open Redirect Bypass Vulnerability
CVSS 7.2
CVE-2026-49380 LOW
Jetbrains TeamCity < 2026.1 - URL Redirection to Untrusted Site ('Open Redirect')
CVSS 3.1
CVE-2026-45307 MEDIUM
Speakr: Open redirect in is_safe_url via parser mismatch on next parameter
CVSS 6.1
CVE-2026-44681 MEDIUM
Authlib: Open Redirect in Authlib OIDC Implicit/Hybrid Authorization
CVSS 6.1
CVE-2026-45335 MEDIUM
WeGIA: Middleware whitelist bypass → open redirect via InternoControle.nextPage
CVSS 5.4
CVE-2026-49059 MEDIUM
WordPress Facebook for WooCommerce plugin <= 3.7.0 - Open Redirection vulnerability
CVSS 4.7
CVE-2026-48924 MEDIUM
Jenkins Bitbucket OAuth Plugin < 0.17 - URL Redirection to Untrusted Site ('Open Redirect')
CVSS 4.3
CVE-2026-44833 MEDIUM
Snipe-IT: Open redirect vulnerability
CVSS 5.9
CVE-2026-48589 MEDIUM
Apache Shiro: Jakarta EE open redirect via untrusted Referer in post-login redirect flow
CVSS 5.4
CVE-2026-44598 MEDIUM
Apache Shiro Jakarta EE module: Open redirect and SSRF (requires valid credentials)
CVSS 5.4
CVE-2026-47070 MEDIUM
HTTP/3 redirect handler leaks Authorization and Cookie headers to cross-origin redirect target in hackney
CVSS 6.1
CVE-2026-48832 LOW
Spip < 4.4.15 - URL Redirection to Untrusted Site ('Open Redirect')
CVSS 3.5
CVE-2026-40295 MEDIUM
Devise: Open Redirect via Unvalidated `request.referrer` in Timeoutable Session Timeout Handler
CVSS 6.1
Details
Vulnerabilities 1,628
Exploit Likelihood Low