Open Redirect Vulnerability in Waku by Waku.js
CVE-2026-49456

3.1LOW

Key Information:

Vendor

Wakujs

Status
Vendor
CVE Published:
3 September 2026

What is CVE-2026-49456?

The Waku minimal React framework has a vulnerability in the unstable_redirect() helper, which allows reflected user-controlled input to be used in HTTP Location response headers without proper validation. This flaw can be exploited to conduct open redirect attacks, redirecting users to malicious external domains. This can facilitate phishing efforts, credential theft, and unauthorized access to sensitive information. Attackers can leverage scheme-relative URLs to bypass common whitelist filters, enhancing the risk of exploitation. The issue has been rectified in version 1.0.0-beta.1.

Affected Version(s)

waku < 1.0.0-beta.1

References

CVSS V3.1

Score:
3.1
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.