Unvalidated URL Redirection in Password Reset Feature of Red Hat Products
CVE-2026-53683
4.3MEDIUM
What is CVE-2026-53683?
The password reset functionality in certain Red Hat products is susceptible to an unvalidated URL redirection vulnerability. Specifically, the reset_password.html file parses query string parameters, utilizing the 'url' parameter as a redirect target without any validation or allowlisting. This flaw allows attackers to redirect users to any arbitrary external site upon completion of the password reset process, potentially leading to phishing attacks and other malicious activities that jeopardize user security.