Open Redirect Vulnerability in oauth-proxy Affects Red Hat
CVE-2026-83589

6.1MEDIUM

Key Information:

Vendor

Red Hat

Vendor
CVE Published:
1 October 2026

What is CVE-2026-83589?

A vulnerability exists in oauth-proxy due to improper validation of the destination redirect parameter during the post-login process. This flaw allows remote attackers to craft malicious links, which, when followed by users, redirect them to arbitrary external sites after authentication. Such open redirects can facilitate phishing attacks, potentially leading to credential theft and unauthorized access.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.