Open Redirection Vulnerability in Popular Password Manager Software
CVE-2026-10837
5.1MEDIUM
What is CVE-2026-10837?
This vulnerability arises from inadequate validation of the X-Forwarded-Host HTTP header, allowing attackers to craft malicious links. When victims click on these links, they may be redirected to attacker-controlled domains. Such redirections can facilitate phishing attempts and other deceptive practices, posing a risk to users' security and trust in the affected password manager software.
Affected Version(s)
Password Manager 0 < 08/07/2025
Password Manager 08/07/2025
