Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-83589— Oauth-proxy: open redirect via /\ and /\t bypass in post-login redirect

Quick assessment

Affected
Red Hat Red Hat OpenShift Container Platform 4
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 oauth-proxy 中发现了一个安全漏洞。该应用程序未能正确验证登录后的重定向目标参数( )。远程攻击者可以利用此漏洞,诱使用户点击一个精心构造的链接,导致用户在完成身份验证后被重定向到任意外部网站。这种开放重定向漏洞可被用于实施钓鱼攻击或窃取用户凭据。

CVSS 6.1 · Medium

Possible ATT&CK Techniques 1 AI

T1566 · Phishing
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-83589

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Oauth-proxy: open redirect via /\ and /\t bypass in post-login redirect
Source: CVE Program / CVE List V5
Vulnerability Description
A flaw was found in oauth-proxy. The application fails to properly validate the destination redirect parameter (`rd`) during post-login redirection. A remote attacker can exploit this vulnerability by enticing a user to follow a specially crafted link, resulting in the user being redirected to an arbitrary external website after authenticating. This open redirect can be leveraged to conduct phishing attacks or credential theft.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
指向未可信站点的URL重定向(开放重定向)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Red Hat Red Hat OpenShift Container Platform 4 - cpe:/a:redhat:openshift:4
Red Hat Red Hat OpenShift Container Platform 4 - cpe:/a:redhat:openshift:4

II. Public POCs for CVE-2026-83589

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-83589

请登录查看更多情报信息。

Other References for CVE-2026-83589 (2)

Same Patch Batch · Red Hat · 2026-10-01 · 4 CVEs total

CVE-2026-96577 7.1 HIGH Oc-mirror__release-4.21: embedded local cache registry listens on all interfaces without a
CVE-2026-103754 5.9 MEDIUM Ansible-runner: ansible-runner: path traversal and symlink escape in unstream_dir() allows
CVE-2026-103641 5.5 MEDIUM Gegl: gegl04: gegl: out-of-bounds read in the radiance hdr uncompressed scanline decoder

IV. Related Vulnerabilities

V. Comments for CVE-2026-83589

No comments yet


Leave a comment