CWE-601: Open Redirect
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.
917 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-4123 — A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redire
- CVE-2026-33506 — DOM-Based XSS in Ory Polis Login Page
- CVE-2025-62428 — Drawing-Captcha APP Host Header Injection in `/register` and `/confirm-email` Endpoints
- CVE-2025-57800 — Audiobookshelf vulnerable to OIDC token exfiltration and account takeover
- CVE-2025-24381 — Dell Unity, version(s) 5.4 and prior, contain(s) an URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A
- CVE-2024-43683 — Improper verification of the Host header in TimeProvider 4100
- CVE-2026-29067 — ZITADEL: Account Takeover Due to Improper Instance Validation in V2 Login
- CVE-2026-28681 — IRRd: web UI host header injection allows password reset poisoning via attacker-controlled email links
- CVE-2025-64101 — ZITADEL Vulnerable to Account Takeover via Malicious Forwarded Header Injection
- CVE-2025-62716 — Plane Vulnerable to Cross-Site Scripting via Open Redirect in ?next_path Parameter
- CVE-2025-48936 — ZITADEL Allows Account Takeover via Malicious X-Forwarded-Proto Header Injection
- CVE-2026-6795 — Open Redirect in DivvyDrive Information Technologies' DivvyDrive
- CVE-2026-54588 — Poweradmin has Host Header Injection in OIDC redirect_uri, SAML ACS/SLO URL, and Logout Redirect Construction.
- CVE-2026-53662 — immich: One-click account takeover via XSS in login page continue redirect
- CVE-2026-43941 — Unvalidated shell.openExternal in electerm allows arbitrary protocol execution via terminal link click
- CVE-2025-6238 — AI Engine 2.8.4 - Insecure OAuth Implementation
- CVE-2024-56734 — Better Auth has an Open Redirect Vulnerability in Verify Email Endpoint
- CVE-2026-61451 — Grav before 1.0.4 Password Reset Token Poisoning via admin_base_url
- CVE-2026-71428 — unstructured: Server-Side Request Forgery in the URL-based partitioning
- CVE-2026-55087 — Etherpad: x-proxy-path header reflected into admin HTML/JS/CSS (cache-poisoning XSS) and concatenated into redirect (open-redirect)
Recently published
- CVE-2026-86756 — Snipe-IT 8.5.0 through 8.6.3 Open Redirect via SAML RelayState
- CVE-2026-78377 — Open Redirect in Yordam Informatics's Library Automation System
- CVE-2026-84389 — A url redirection to untrusted site ('open redirect') vulnerability in Fortinet FortiSIEM 7.5.0 through 7.5.1, FortiSIEM
- CVE-2026-86351 — MISP User Homepage Validation Allows Authenticated Open Redirect via Protocol-Relative URL
- CVE-2026-86256 — wger before 2.6 Open Redirect via trainer-login next parameter
- CVE-2026-86205 — h3 before 2.0.1-rc.18 Open Redirect via redirectBack()
- CVE-2026-85676 — Dub Open Redirect via Unrestricted redir_url Parameter
- CVE-2026-53728 — Medplum - Improper Validation of Redirect URI in External Auth Callback allows Authorization Code Leakage
- CVE-2026-49456 — Waku: Open Redirect via `unstable_redirect` Helper
- CVE-2026-82731 — Unescaped path parameters in AshTypescript generated TypeScript client allow request redirection
- CVE-2026-78079 — Joomla Extension - joomshaper.com - Privileged File Upload Bypass via Content Spoofing in Helix Ultimate < 2.2.10
- CVE-2026-82467 — Rodauth before 2.47.0 Open Redirect via Return-to Path
- CVE-2026-82464 — pac4j-core before 6.5.6 Open Redirect via Backslash Logout
- CVE-2026-55834 — Pocket ID: Open Redirect on the OIDC /authorize page via unvalidated redirect_uri with prompt=none
- CVE-2026-82274 — Twenty Open Redirect via OAuth Propagator Callback
- CVE-2026-59355 — Spring Authorization Server: Open Redirect via request_uri parameter
- CVE-2026-81036 — Stalwart Mail Server through 0.16.19 Authorization Code Disclosure via Unvalidated OAuth redirect_uri
- CVE-2026-81029 — OpenMetadata before 2.0.0 JWT Disclosure via Unvalidated SAML and OIDC Redirect URI
- CVE-2026-80200 — Kimai before 2.53.0 Open Redirect via RelayState
- CVE-2026-79786 — Coroot 1.20.2 through 1.24.5 Unvalidated Redirect URI in MCP OAuth Client Registration