CVE-2026-83589

medium

Description

A flaw was found in oauth-proxy. The application fails to properly validate the destination redirect parameter (`rd`) during post-login redirection. A remote attacker can exploit this vulnerability by enticing a user to follow a specially crafted link, resulting in the user being redirected to an arbitrary external website after authenticating. This open redirect can be leveraged to conduct phishing attacks or credential theft.

References

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-90589

https://bugzilla.redhat.com/show_bug.cgi?id=2518379

https://access.redhat.com/security/cve/CVE-2026-83589

Details

Source: Mitre, NVD

Published: 2026-10-01

Updated: 2026-10-01

Risk Information

CVSS v2

Base Score: 6.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:N

Severity: Medium

CVSS v3

Base Score: 6.1

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Severity: Medium

EPSS

EPSS: 0.0019