CVE-2026-83589 PUBLISHED

Oauth-proxy: open redirect via /\ and /\t bypass in post-login redirect

Assigner: redhat
Reserved: 31.08.2026 Published: 01.10.2026 Updated: 01.10.2026

A flaw was found in oauth-proxy. The application fails to properly validate the destination redirect parameter (rd) during post-login redirection. A remote attacker can exploit this vulnerability by enticing a user to follow a specially crafted link, resulting in the user being redirected to an arbitrary external website after authenticating. This open redirect can be leveraged to conduct phishing attacks or credential theft.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CVSS Score: 6.1

Product Status

Vendor Red Hat
Product Red Hat OpenShift Container Platform 4
Versions Default: affected
Vendor Red Hat
Product Red Hat OpenShift Container Platform 4
Versions Default: affected

Workarounds

Red Hat has not identified any known mitigations for this issue. Customers are advised to apply the available security update when released.

References

Problem Types

  • URL Redirection to Untrusted Site ('Open Redirect') CWE