Red HatCVE-2026-83589
Red Hat OpenShift Container Platform 4: open redirect
Medium6.1CVE-2026-83589 · Published Oct 1, 2026
A flaw was found in oauth-proxy. The application fails to properly validate the destination redirect parameter (`rd`) during post-login redirection. A remote attacker can exploit this vulnerability by enticing a user to follow a specially crafted link, resulting in the user being redirected to an arbitrary external website after authenticating. This open redirect can be leveraged to conduct phishing attacks or credential theft.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Red Hat OpenShift Container Platform 4 Product | all versions | No fix yet |
| all versions | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-601
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Oct 1 | Red Hat oc-mirror. During mirroring operations: missing authentication | High7.1 | No fix yet |
| Oct 1 | Red Hat GEGL: out-of-bounds read | Medium5.5 | No fix yet |
| Sep 30 | Red Hat Enterprise Linux: request smuggling | Medium5.3 | No fix yet |
| Sep 30 | Assisted Installer for Red Hat OpenShift Container Platform : path traversal | High7.3 | No fix yet |
| Sep 30 | A trust-boundary flaw in CRI-O's sandbox state persistence | High7.8 | No fix yet |
| Sep 30 | Red Hat rpm. RPMTAG_FILESIGNATURES: heap buffer overflow | High7.1 | No fix yet |