VDB

CVE-2026-83589

CVE-2026-83589 PUBLISHED CVSS 6.1 MEDIUM

Reported by redhat · Published October 1, 2026

A flaw was found in oauth-proxy. The application fails to properly validate the destination redirect parameter (`rd`) during post-login redirection. A remote attacker can exploit this vulnerability by enticing a user to follow a specially crafted link, resulting in the user being redirected to an arbitrary external website after authenticating. This open redirect can be leveraged to conduct phishing attacks or credential theft.

Risk Scores

CVSS 3.1
6.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Affected Products

VendorProductVersions
Red HatRed Hat OpenShift Container Platform 4.201790704224
Red HatRed Hat OpenShift Container Platform 4.211790706478
Red HatRed Hat OpenShift Container Platform 4.221790724885
Red HatRed Hat OpenShift Container Platform 4
Red HatRed Hat OpenShift Container Platform 4
Red HatRed Hat OpenShift Container Platform 4.221790724885
Red HatRed Hat OpenShift Container Platform 4.201790704224
Red HatRed Hat OpenShift Container Platform 4.211790706478
Red HatRed Hat OpenShift Container Platform 4

Timeline

  • Oct 1, 2026 Coalition ESS Score
  • Oct 1, 2026 CVE Published
  • Oct 2, 2026 EPSS Score
  • Oct 7, 2026 EPSS Score
  • Oct 7, 2026 CVE Updated
  • Oct 7, 2026 Distribution Patch
  • Oct 7, 2026 Distribution Patch
  • Oct 7, 2026 Distribution Patch
  • Oct 7, 2026 Security Advisory
  • Oct 7, 2026 Security Advisory
  • Oct 7, 2026 Security Advisory

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›