Skip to content
Red HatCVE-2026-19078

Red Hat OpenShift Container Platform 4: open redirect

Medium4.3CVE-2026-19078 · Published Aug 11, 2026 · updated Aug 14, 2026

A flaw was found in the oauth-server component. This open redirect vulnerability occurs when the 'then' parameter in the grant approval handler is not properly validated. A remote attacker can craft a malicious URL that, when approved or denied by an authenticated user, redirects them to an attacker-controlled website. This could enable phishing attacks, potentially tricking users into revealing sensitive information.

Red Hat advisory

Affected versions

PackageAffectedFixed in
Red Hat OpenShift Container Platform 4
Product
all versionsNo fix yet
all versionsNo fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-601

More Red Hat advisories

All Red Hat
Advisory
Red Hat FreeIPA: improper authorization
High8.2Aug 11
Red Hat search-v2-api. The authentication middleware: authentication bypass
High7.5Aug 11
Red Hat acm-search-v2-api-rhel9.: information disclosure
Medium5.3Aug 11
Red Hat insights-client.: information disclosure
High7.1Aug 11
Red Hat insights-client. A compromised managed cluster: information disclosure
Medium6.8Aug 11
Red Hat insights-client: secrets in logs
Medium6.3Aug 11

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.