Security Vulnerability in Warpgate Open Source Bastion Host
CVE-2026-91165
2.4LOW
What is CVE-2026-91165?
Warpgate, an open-source bastion host for SSH, HTTPS, and MySQL on Linux, exhibits a vulnerability in its handling of single sign-on (SSO) return paths. The flaw arises from the inadequate neutralization of script-closing sequences in the response generated by the SSO mechanism before version 0.27.6. This allows an attacker to inject harmful values through parameters stored in redirect paths or error messages from identity providers (IdPs). If successfully exploited, users may encounter spoofed content such as misleading login forms or redirects, though the security policy mitigates script execution. To address this issue, users should update to Warpgate version 0.27.6 or later.
Affected Version(s)
warpgate < 0.27.6
