Open Redirect Vulnerability in OAuth Server Component of Red Hat Products
CVE-2026-19078

4.3MEDIUM

Key Information:

Vendor

Red Hat

Vendor
CVE Published:
11 August 2026

What is CVE-2026-19078?

A security flaw has been identified in the oauth-server component of Red Hat products that allows for open redirection. This vulnerability stems from inadequate validation of the 'then' parameter in the grant approval handler. Attackers can exploit this flaw by crafting malicious URLs that redirect authenticated users to unauthorized locations. If a user approves or denies a request containing such a link, they may inadvertently expose sensitive information through phishing attacks aimed at tricking them into revealing their credentials.

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Khalil Lemtaffah (Nokia), Kien Pham (Ninh Thanh Cyber Security (NTCS)), and Ta Duc Thien (Ninh Thanh Cyber Security (NTCS)) for reporting this issue.
.