On this page
CWE-601: URL Redirection to Untrusted Site ('Open Redirect')
Weakness Summary
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.
- Canonical source: MITRE CWE-601 (opens in a new tab)
- Published Atomicorp CVE observations: 67
- Distinct affected products in those observations: 58
- Active Atomicorp rules associated with this weakness: 39
Atomicorp Research Context
Atomicorp has published CVE-specific research observations associated with this weakness category. Each linked CVE page states whether the tested request was detected or blocked and is the authoritative customer-facing finding.
The CVEs and rules shown here are selected published examples, not a complete list of Atomicorp protections. If a CWE, CVE, or rule is absent from this page, no conclusion should be drawn about whether Atomicorp protects against that weakness or attack method.
A CWE describes a class of software weakness. It does not identify one exploit request, and association with a CWE does not mean that every vulnerability or exploitation path in that category is detected or blocked.
Selected Published CVE Observations
| CVE | Vulnerability | Product | Atomicorp finding | Observed rules |
|---|---|---|---|---|
| CVE-2026-79662 | Ech0 before 4.7.3 OAuth Redirect URI Validation Bypass | Ech0 | Attack Blocked by Atomicorp | 340162 , 340163 , 340165 , 344365 |
| CVE-2026-75833 | Grav API Plugin Open Redirect via Backslash Bypass | grav | Attack Blocked by Atomicorp | 344365 |
| CVE-2026-34931 | hoppscotch: Improper loopback redirect_uri validation in device-login flow | hoppscotch | Attack Blocked by Atomicorp | 344365 |
| CVE-2026-81029 | OpenMetadata before 2.0.0 JWT Disclosure via Unvalidated SAML and OIDC Redirect URI | OpenMetadata | Attack Blocked by Atomicorp | 344365 |
| CVE-2026-81036 | Stalwart Mail Server through 0.16.19 Authorization Code Disclosure via Unvalidated OAuth redirect_uri | stalwart | Attack Blocked by Atomicorp | 344365 |
| CVE-2026-63094 | SigNoz < 0.134.0 SSO OAuth State Manipulation Session Token Theft | signoz | Attack Blocked by Atomicorp | 344365 |
| CVE-2026-53728 | Medplum - Improper Validation of Redirect URI in External Auth Callback allows Authorization Code Leakage | medplum | Attack Blocked by Atomicorp | 340162 , 340163 , 344365 |
| CVE-2026-79786 | Coroot 1.20.2 through 1.24.5 Unvalidated Redirect URI in MCP OAuth Client Registration | coroot | Attack Blocked by Atomicorp | 344365 |
| CVE-2019-3778 | Spring Security OAuth - Open Redirector | spring security oauth | Attack Blocked by Atomicorp | 390703 , 390727 , 392301 , 392648 |
| CVE-2013-2621 | Telaen => v1.3.1 - Open Redirect | telaen | Attack Blocked by Atomicorp | 320007 |
| CVE-2015-4668 | Xceedium Xsuite - Multiple Vulnerabilities | xsuite | Attack Blocked by Atomicorp | 320464 , 320465 , 333141 , 340023 , 340099 , 340147 , 340148 , 341099 , 341256 , 342259 , 344360 , 344361 , 344363 , 344370 , 346755 , 347198 , 350148 , 390726 , 392301 , 392647 , 392648 |
| CVE-2017-1000163 | Phoenix Framework - Open Redirect | phoenix | Attack Blocked by Atomicorp | 344365 |
| CVE-2018-12300 | Seagate NAS OS 4.3.15.1 - Open Redirect | nas os | Attack Blocked by Atomicorp | 340163 |
| CVE-2019-1943 | CISCO Small Business 200 / 300 / 500 Switches - Multiple Vulnerabilities | sg200-50 firmware | Attack Blocked by Atomicorp | 390727 , 392301 , 392648 |
| CVE-2020-13121 | Submitty <= 20.04.01 - Open Redirect | submitty | Attack Blocked by Atomicorp | 340162 , 340163 |
| CVE-2020-18268 | Z-Blog <=1.5.2 - Open Redirect | z-blogphp | Attack Blocked by Atomicorp | 390500 , 390501 |
| CVE-2021-24165 | WordPress Ninja Forms <3.4.34 - Open Redirect | ninja forms | Detected by Atomicorp | 377360 |
| CVE-2021-24210 | WordPress PhastPress <1.111 - Open Redirect | phastpress | Attack Blocked by Atomicorp | 340162 , 340163 |
| CVE-2021-24838 | WordPress AnyComment <0.3.5 - Open Redirect | anycomment | Attack Blocked by Atomicorp | 390145 |
| CVE-2021-25074 | WordPress WebP Converter for Media < 4.0.3 - Unauthenticated Open Redirect | webp converter for media | Attack Blocked by Atomicorp | 340162 , 340163 |
| CVE-2021-32478 | Moodle 3.8-3.10.3 - Reflected XSS & Open Redirect | moodle | Attack Blocked by Atomicorp | 346755 , 350148 |
| CVE-2024-0250 | Analytics Insights for Google Analytics 4 < 6.3 - Open Redirect | analytics insights | Attack Blocked by Atomicorp | 340162 , 340163 |
| CVE-2024-25608 | Liferay Portal - Open Redirect | digital experience platform,liferay portal | Detected by Atomicorp | 398005 |
| CVE-2024-3032 | WordPress Themify Builder < 7.5.8 - Open Redirect | builder | Detected by Atomicorp | 377360 |
| CVE-2025-32970 | XWiki WYSIWYG API - Open Redirect | xwiki | Attack Blocked by Atomicorp | 340162 , 340163 |
| CVE-2026-1296 | Frontend Post Submission Manager Lite <= 1.2.7 - Open Redirect | Frontend Post Submission Manager Lite – Frontend Posting WordPress Plugin | Detected by Atomicorp | 377360 |
| CVE-2026-33213 | Redash: Open redirect vulnerability in post-login redirect handling | redash | Attack Blocked by Atomicorp | 344365 |
| CVE-2026-34442 | FreeScout: Host Header Injection Leading to External Resource Loading and Open Redirect in FreeScout | freescout | Attack Blocked by Atomicorp | 340165 , 344365 |
| CVE-2026-34847 | hoppscotch: Open redirect via /enter?redirect= | hoppscotch | Attack Blocked by Atomicorp | 344365 |
| CVE-2026-35404 | Open edX Platform has an Open Redirect in Survey Views via Unvalidated redirect_url Parameter | openedx | Attack Blocked by Atomicorp | 344365 |
| CVE-2026-40295 | Devise: Open Redirect via Unvalidated request.referrer in Timeoutable Session Timeout Handler | devise | Attack Blocked by Atomicorp | 344365 |
| CVE-2026-55087 | Etherpad: x-proxy-path header reflected into admin HTML/JS/CSS (cache-poisoning XSS) and concatenated into redirect (ope | etherpad | Attack Blocked by Atomicorp | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-75628 | Punk::OAuth2 versions before 0.03 for Perl allow an attacker-chosen off-site redirect after login because same_origin_pa | - | Attack Blocked by Atomicorp | 344365 |
| CVE-2017-14725 | WordPress < 4.8.2 - Authenticated Open Redirect | WordPress | Detected by Atomicorp | 377360 |
| CVE-2017-3528 | Oracle E-Business Suite 12.1.3/12.2.x - Open Redirect | applications framework | Attack Blocked by Atomicorp | 344365 |
| CVE-2019-11269 | Spring Security OAuth - Open Redirector | spring security oauth | Attack Blocked by Atomicorp | 390703 , 390727 , 392301 , 392648 |
| CVE-2026-18266 | Dify AI Workflow oauth_redirect_url Open Redirect Vulnerability | Dify | Attack Blocked by Atomicorp | 344365 |
| CVE-2026-16336 | trinodb trino OAuth2/OIDC ExternalUriInfo.java redirect | trino | Attack Blocked by Atomicorp | 340165 , 344365 |
| CVE-2026-63768 | cal.diy 6.2.0 Conferencing OAuth Callback Open Redirect via Unsigned State | cal.diy | Attack Blocked by Atomicorp | 340162 , 340163 , 340165 , 344365 |
| CVE-2026-80200 | Kimai before 2.53.0 Open Redirect via RelayState | kimai | Attack Blocked by Atomicorp | 344365 |
| CVE-2026-82274 | Twenty Open Redirect via OAuth Propagator Callback | twenty | Attack Blocked by Atomicorp | 340162 , 340163 , 340165 , 344365 |
| CVE-2026-85676 | Dub Open Redirect via Unrestricted redir_url Parameter | dub | Attack Blocked by Atomicorp | 344365 |
| CVE-2026-86205 | h3 before 2.0.1-rc.18 Open Redirect via redirectBack() | h3 | Attack Blocked by Atomicorp | 344365 |
| CVE-2026-86756 | Snipe-IT 8.5.0 through 8.6.3 Open Redirect via SAML RelayState | snipe-it | Attack Blocked by Atomicorp | 344365 |
| CVE-2026-32113 | Discourse: Open redirect via sso_destination_url cookie in enter | discourse | Attack Blocked by Atomicorp | 344365 |
| CVE-2026-35396 | WeGIA - Open Redirect - IsaidaControle - listarId() - Unvalidated $_GET['nextPage'] | wegia | Attack Blocked by Atomicorp | 340162 , 340163 , 340165 , 344365 |
| CVE-2026-35398 | WeGIA - Open Redirect - OrigemControle - listarTodos() & listarId_Nome() - Unvalidated $_GET['nextPage'] | wegia | Attack Blocked by Atomicorp | 340162 , 340163 , 340165 , 344365 |
| CVE-2026-35472 | WeGIA - Open Redirect - EstoqueControle - listarTodos() - Unvalidated $_GET['nextPage'] | wegia | Attack Blocked by Atomicorp | 340162 , 340163 , 340165 , 344365 |
| CVE-2026-35473 | WeGIA - Open Redirect - IentradaControle - listarId() - Unvalidated $_GET['nextPage'] | wegia | Attack Blocked by Atomicorp | 340162 , 340163 , 340165 , 344365 |
| CVE-2026-35474 | WeGIA - Open Redirect - atualizacao redirection - Unvalidated $_GET['redirect'] | wegia | Attack Blocked by Atomicorp | 344365 |
| CVE-2026-35475 | WeGIA - Open Redirect - backup redirection — Unvalidated $_GET['redirect'] | wegia | Attack Blocked by Atomicorp | 340165 , 344365 |
| CVE-2026-42350 | Kargo: Open Redirect in UI OIDC Login Flow via redirectTo Query Parameter | kargo | Attack Blocked by Atomicorp | 344365 |
| CVE-2026-55185 | Miniflux 2: Open Redirect Bypass | v2 | Attack Blocked by Atomicorp | 344365 |
| CVE-2026-66414 | Leantime Open Redirect in Login Controller via redirectUrl Parameter | Leantime | Attack Blocked by Atomicorp | 344365 |
| CVE-2026-73671 | Saurus CMS Unauthenticated Open Redirect via logout url parameter | Saurus CMS Community Edition | Attack Blocked by Atomicorp | 344365 |
| CVE-2026-86256 | wger before 2.6 Open Redirect via trainer-login next parameter | wger | Attack Blocked by Atomicorp | 344365 |
| CVE-2026-51564 | the redirect parameter in Milk admin <=0.9.8 Open Redirect Vulnerability | - | Attack Blocked by Atomicorp | 344365 |
| CVE-2026-43924 | FOSSBilling has an open redirect via administrator-configured redirect targets | FOSSBilling | Attack Blocked by Atomicorp | 344365 |
| CVE-2026-14236 | Contact Form 7 – PayPal & Stripe Add-on < 2.5 - Open Redirect | Contact Form 7 | Attack Blocked by Atomicorp | 344365 |
| CVE-2008-1547 | Microsoft OWA Exchange Server 2003 - 'redir.asp' Open Redirection | exchange server | Attack Blocked by Atomicorp | 390716 |
| CVE-2026-35411 | Directus is an Open Redirect in Admin 2FA Setup Page | directus | Attack Blocked by Atomicorp | 344365 |
| CVE-2026-48012 | Shopware SSO referer trust leading to an arbitrary redirect target | shopware | Attack Blocked by Atomicorp | 344365 |
| CVE-2026-53683 | Freeipa: idm: idm/freeipa web ui - client-side open redirect in reset_password.html | Red Hat Enterprise Linux 10 | Attack Blocked by Atomicorp | 340163 , 344365 |
| CVE-2026-55834 | Pocket ID: Open Redirect on the OIDC /authorize page via unvalidated redirect_uri with prompt=none | pocket-id | Attack Blocked by Atomicorp | 340162 , 340163 , 340165 , 344365 |
| CVE-2026-11477 | hs-web hsweb-framework OAuth2 Client OAuth2Client.java OAuth2Client redirect | hsweb-framework | Attack Blocked by Atomicorp | 340162 , 340163 , 340165 , 344365 |
| CVE-2026-67350 | Serendipity < 2.6.1 Open Redirect via exit.php | Serendipity | Attack Blocked by Atomicorp | 344365 |
| CVE-2026-11502 | JeecgBoot Third-Party Login ThirdLoginController.java HttpServletResponse.sendRedirect redirect | JeecgBoot | Attack Blocked by Atomicorp | 340162 , 340163 , 340165 , 344365 |
Associated Atomicorp WAF Rules
| Rule | Status | Behavior |
|---|---|---|
| 320007 | Active | disruptive (deny) |
| 320464 | Active | disruptive (deny) |
| 320465 | Active | disruptive (deny) |
| 333140 | Active | disruptive (deny) |
| 333141 | Active | disruptive (deny) |
| 340023 | Active | disruptive (deny) |
| 340087 | Active | disruptive (deny) |
| 340095 | Active | disruptive (deny) |
| 340099 | Active | disruptive (deny) |
| 340147 | Active | disruptive (deny) |
| 340148 | Active | disruptive (deny) |
| 340162 | Active | disruptive (deny) |
| 340163 | Active | disruptive (deny) |
| 340165 | Active | disruptive (deny) |
| 341099 | Active | disruptive (deny) |
| 341256 | Active | disruptive (deny) |
| 341266 | Active | disruptive (deny) |
| 342259 | Active | disruptive (deny) |
| 344360 | Active | disruptive (deny) |
| 344361 | Active | disruptive (deny) |
| 344363 | Active | disruptive (deny) |
| 344365 | Active | disruptive (deny) |
| 344370 | Active | disruptive (deny) |
| 346755 | Active | disruptive (deny) |
| 347198 | Active | disruptive (deny) |
| 350147 | Active | disruptive (deny) |
| 350148 | Active | disruptive (deny) |
| 377360 | Active | non-disruptive (pass) |
| 390145 | Active | disruptive (deny) |
| 390500 | Active | non-disruptive (not available) |
| 390501 | Active | disruptive (deny) |
| 390703 | Active | disruptive (deny) |
| 390716 | Active | disruptive (deny) |
| 390726 | Active | disruptive (deny) |
| 390727 | Active | disruptive (deny) |
| 392301 | Active | disruptive (deny) |
| 392647 | Active | disruptive (deny) |
| 392648 | Active | disruptive (deny) |
| 398005 | Active | non-disruptive (pass) |
Related MITRE CAPEC Context
MITRE associates this CWE with the following attack-pattern entries. These taxonomy relationships are context, not Atomicorp coverage claims: