Open Redirect Vulnerability in Rodauth Affected by Leading Double Slashes
CVE-2026-82467
4.9MEDIUM
What is CVE-2026-82467?
Rodauth versions before 2.47.0 are susceptible to an open redirect vulnerability due to insufficient validation of protocol-relative return-to paths. This flaw primarily affects the confirm_password, login_return_to_requested_location, and two_factor_auth_return_to_requested_location features. Attackers can exploit this weakness by constructing paths with leading double slashes, causing browsers to treat them as protocol-relative URLs. As a result, authenticated users may be redirected to malicious sites controlled by attackers after logging in or confirming their passwords, leading to potential security breaches and data compromise.
Affected Version(s)
rodauth 0 < 2.47.0
