CVE-2026-82467
MEDIUM
4,9
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: passive
Confidentiality: N/A
Integrity: N/A
Availability: N/A
MEDIUM
4,7
Source: [email protected]
Attack Vector: network
Attack Complexity: high
Privileges Required: none
User Interaction: required
Scope: changed
Confidentiality: low
Integrity: low
Availability: none
Description
AI Translation Available
Rodauth before 2.47.0 fails to validate protocol-relative return-to paths in confirm_password, login_return_to_requested_location, and two_factor_auth_return_to_requested_location features. Attackers can craft paths with leading double slashes that browsers resolve as protocol-relative URLs, redirecting authenticated users to attacker-controlled sites after login or password confirmation.
601
URL Redirection to Untrusted Site ('Open Redirect')
DraftCommon Consequences
Security Scopes Affected:
Access Control
Confidentiality
Other
Potential Impacts:
Bypass Protection Mechanism
Gain Privileges Or Assume Identity
Other
Applicable Platforms
Technologies:
Web Based, Web Server
https://github.com/jeremyevans/rodauth
https://github.com/jeremyevans/rodauth/commit/295044a92e358479afdf84f905dd5efe8…
https://github.com/jeremyevans/rodauth/security/advisories/GHSA-h9m4-vm9w-h43m
https://www.vulncheck.com/advisories/rodauth-before-2.47.0-open-redirect-via-re…