On this page

CWE-601: URL Redirection to Untrusted Site ('Open Redirect')

Weakness Summary

The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.

  • Canonical source: MITRE CWE-601 (opens in a new tab)
  • Published Atomicorp CVE observations: 67
  • Distinct affected products in those observations: 58
  • Active Atomicorp rules associated with this weakness: 39

Atomicorp Research Context

Atomicorp has published CVE-specific research observations associated with this weakness category. Each linked CVE page states whether the tested request was detected or blocked and is the authoritative customer-facing finding.

The CVEs and rules shown here are selected published examples, not a complete list of Atomicorp protections. If a CWE, CVE, or rule is absent from this page, no conclusion should be drawn about whether Atomicorp protects against that weakness or attack method.

A CWE describes a class of software weakness. It does not identify one exploit request, and association with a CWE does not mean that every vulnerability or exploitation path in that category is detected or blocked.

Selected Published CVE Observations

CVEVulnerabilityProductAtomicorp findingObserved rules
CVE-2026-79662Ech0 before 4.7.3 OAuth Redirect URI Validation BypassEch0Attack Blocked by Atomicorp340162 , 340163 , 340165 , 344365
CVE-2026-75833Grav API Plugin Open Redirect via Backslash BypassgravAttack Blocked by Atomicorp344365
CVE-2026-34931hoppscotch: Improper loopback redirect_uri validation in device-login flowhoppscotchAttack Blocked by Atomicorp344365
CVE-2026-81029OpenMetadata before 2.0.0 JWT Disclosure via Unvalidated SAML and OIDC Redirect URIOpenMetadataAttack Blocked by Atomicorp344365
CVE-2026-81036Stalwart Mail Server through 0.16.19 Authorization Code Disclosure via Unvalidated OAuth redirect_uristalwartAttack Blocked by Atomicorp344365
CVE-2026-63094SigNoz < 0.134.0 SSO OAuth State Manipulation Session Token TheftsignozAttack Blocked by Atomicorp344365
CVE-2026-53728Medplum - Improper Validation of Redirect URI in External Auth Callback allows Authorization Code LeakagemedplumAttack Blocked by Atomicorp340162 , 340163 , 344365
CVE-2026-79786Coroot 1.20.2 through 1.24.5 Unvalidated Redirect URI in MCP OAuth Client RegistrationcorootAttack Blocked by Atomicorp344365
CVE-2019-3778Spring Security OAuth - Open Redirectorspring security oauthAttack Blocked by Atomicorp390703 , 390727 , 392301 , 392648
CVE-2013-2621Telaen => v1.3.1 - Open RedirecttelaenAttack Blocked by Atomicorp320007
CVE-2015-4668Xceedium Xsuite - Multiple VulnerabilitiesxsuiteAttack Blocked by Atomicorp320464 , 320465 , 333141 , 340023 , 340099 , 340147 , 340148 , 341099 , 341256 , 342259 , 344360 , 344361 , 344363 , 344370 , 346755 , 347198 , 350148 , 390726 , 392301 , 392647 , 392648
CVE-2017-1000163Phoenix Framework - Open RedirectphoenixAttack Blocked by Atomicorp344365
CVE-2018-12300Seagate NAS OS 4.3.15.1 - Open Redirectnas osAttack Blocked by Atomicorp340163
CVE-2019-1943CISCO Small Business 200 / 300 / 500 Switches - Multiple Vulnerabilitiessg200-50 firmwareAttack Blocked by Atomicorp390727 , 392301 , 392648
CVE-2020-13121Submitty <= 20.04.01 - Open RedirectsubmittyAttack Blocked by Atomicorp340162 , 340163
CVE-2020-18268Z-Blog <=1.5.2 - Open Redirectz-blogphpAttack Blocked by Atomicorp390500 , 390501
CVE-2021-24165WordPress Ninja Forms <3.4.34 - Open Redirectninja formsDetected by Atomicorp377360
CVE-2021-24210WordPress PhastPress <1.111 - Open RedirectphastpressAttack Blocked by Atomicorp340162 , 340163
CVE-2021-24838WordPress AnyComment <0.3.5 - Open RedirectanycommentAttack Blocked by Atomicorp390145
CVE-2021-25074WordPress WebP Converter for Media < 4.0.3 - Unauthenticated Open Redirectwebp converter for mediaAttack Blocked by Atomicorp340162 , 340163
CVE-2021-32478Moodle 3.8-3.10.3 - Reflected XSS & Open RedirectmoodleAttack Blocked by Atomicorp346755 , 350148
CVE-2024-0250Analytics Insights for Google Analytics 4 < 6.3 - Open Redirectanalytics insightsAttack Blocked by Atomicorp340162 , 340163
CVE-2024-25608Liferay Portal - Open Redirectdigital experience platform,liferay portalDetected by Atomicorp398005
CVE-2024-3032WordPress Themify Builder < 7.5.8 - Open RedirectbuilderDetected by Atomicorp377360
CVE-2025-32970XWiki WYSIWYG API - Open RedirectxwikiAttack Blocked by Atomicorp340162 , 340163
CVE-2026-1296Frontend Post Submission Manager Lite <= 1.2.7 - Open RedirectFrontend Post Submission Manager Lite – Frontend Posting WordPress PluginDetected by Atomicorp377360
CVE-2026-33213Redash: Open redirect vulnerability in post-login redirect handlingredashAttack Blocked by Atomicorp344365
CVE-2026-34442FreeScout: Host Header Injection Leading to External Resource Loading and Open Redirect in FreeScoutfreescoutAttack Blocked by Atomicorp340165 , 344365
CVE-2026-34847hoppscotch: Open redirect via /enter?redirect=hoppscotchAttack Blocked by Atomicorp344365
CVE-2026-35404Open edX Platform has an Open Redirect in Survey Views via Unvalidated redirect_url ParameteropenedxAttack Blocked by Atomicorp344365
CVE-2026-40295Devise: Open Redirect via Unvalidated request.referrer in Timeoutable Session Timeout HandlerdeviseAttack Blocked by Atomicorp344365
CVE-2026-55087Etherpad: x-proxy-path header reflected into admin HTML/JS/CSS (cache-poisoning XSS) and concatenated into redirect (opeetherpadAttack Blocked by Atomicorp333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-75628Punk::OAuth2 versions before 0.03 for Perl allow an attacker-chosen off-site redirect after login because same_origin_pa-Attack Blocked by Atomicorp344365
CVE-2017-14725WordPress < 4.8.2 - Authenticated Open RedirectWordPressDetected by Atomicorp377360
CVE-2017-3528Oracle E-Business Suite 12.1.3/12.2.x - Open Redirectapplications frameworkAttack Blocked by Atomicorp344365
CVE-2019-11269Spring Security OAuth - Open Redirectorspring security oauthAttack Blocked by Atomicorp390703 , 390727 , 392301 , 392648
CVE-2026-18266Dify AI Workflow oauth_redirect_url Open Redirect VulnerabilityDifyAttack Blocked by Atomicorp344365
CVE-2026-16336trinodb trino OAuth2/OIDC ExternalUriInfo.java redirecttrinoAttack Blocked by Atomicorp340165 , 344365
CVE-2026-63768cal.diy 6.2.0 Conferencing OAuth Callback Open Redirect via Unsigned Statecal.diyAttack Blocked by Atomicorp340162 , 340163 , 340165 , 344365
CVE-2026-80200Kimai before 2.53.0 Open Redirect via RelayStatekimaiAttack Blocked by Atomicorp344365
CVE-2026-82274Twenty Open Redirect via OAuth Propagator CallbacktwentyAttack Blocked by Atomicorp340162 , 340163 , 340165 , 344365
CVE-2026-85676Dub Open Redirect via Unrestricted redir_url ParameterdubAttack Blocked by Atomicorp344365
CVE-2026-86205h3 before 2.0.1-rc.18 Open Redirect via redirectBack()h3Attack Blocked by Atomicorp344365
CVE-2026-86756Snipe-IT 8.5.0 through 8.6.3 Open Redirect via SAML RelayStatesnipe-itAttack Blocked by Atomicorp344365
CVE-2026-32113Discourse: Open redirect via sso_destination_url cookie in enterdiscourseAttack Blocked by Atomicorp344365
CVE-2026-35396WeGIA - Open Redirect - IsaidaControle - listarId() - Unvalidated $_GET['nextPage']wegiaAttack Blocked by Atomicorp340162 , 340163 , 340165 , 344365
CVE-2026-35398WeGIA - Open Redirect - OrigemControle - listarTodos() & listarId_Nome() - Unvalidated $_GET['nextPage']wegiaAttack Blocked by Atomicorp340162 , 340163 , 340165 , 344365
CVE-2026-35472WeGIA - Open Redirect - EstoqueControle - listarTodos() - Unvalidated $_GET['nextPage']wegiaAttack Blocked by Atomicorp340162 , 340163 , 340165 , 344365
CVE-2026-35473WeGIA - Open Redirect - IentradaControle - listarId() - Unvalidated $_GET['nextPage']wegiaAttack Blocked by Atomicorp340162 , 340163 , 340165 , 344365
CVE-2026-35474WeGIA - Open Redirect - atualizacao redirection - Unvalidated $_GET['redirect']wegiaAttack Blocked by Atomicorp344365
CVE-2026-35475WeGIA - Open Redirect - backup redirection — Unvalidated $_GET['redirect']wegiaAttack Blocked by Atomicorp340165 , 344365
CVE-2026-42350Kargo: Open Redirect in UI OIDC Login Flow via redirectTo Query ParameterkargoAttack Blocked by Atomicorp344365
CVE-2026-55185Miniflux 2: Open Redirect Bypassv2Attack Blocked by Atomicorp344365
CVE-2026-66414Leantime Open Redirect in Login Controller via redirectUrl ParameterLeantimeAttack Blocked by Atomicorp344365
CVE-2026-73671Saurus CMS Unauthenticated Open Redirect via logout url parameterSaurus CMS Community EditionAttack Blocked by Atomicorp344365
CVE-2026-86256wger before 2.6 Open Redirect via trainer-login next parameterwgerAttack Blocked by Atomicorp344365
CVE-2026-51564the redirect parameter in Milk admin <=0.9.8 Open Redirect Vulnerability-Attack Blocked by Atomicorp344365
CVE-2026-43924FOSSBilling has an open redirect via administrator-configured redirect targetsFOSSBillingAttack Blocked by Atomicorp344365
CVE-2026-14236Contact Form 7 – PayPal & Stripe Add-on < 2.5 - Open RedirectContact Form 7Attack Blocked by Atomicorp344365
CVE-2008-1547Microsoft OWA Exchange Server 2003 - 'redir.asp' Open Redirectionexchange serverAttack Blocked by Atomicorp390716
CVE-2026-35411Directus is an Open Redirect in Admin 2FA Setup PagedirectusAttack Blocked by Atomicorp344365
CVE-2026-48012Shopware SSO referer trust leading to an arbitrary redirect targetshopwareAttack Blocked by Atomicorp344365
CVE-2026-53683Freeipa: idm: idm/freeipa web ui - client-side open redirect in reset_password.htmlRed Hat Enterprise Linux 10Attack Blocked by Atomicorp340163 , 344365
CVE-2026-55834Pocket ID: Open Redirect on the OIDC /authorize page via unvalidated redirect_uri with prompt=nonepocket-idAttack Blocked by Atomicorp340162 , 340163 , 340165 , 344365
CVE-2026-11477hs-web hsweb-framework OAuth2 Client OAuth2Client.java OAuth2Client redirecthsweb-frameworkAttack Blocked by Atomicorp340162 , 340163 , 340165 , 344365
CVE-2026-67350Serendipity < 2.6.1 Open Redirect via exit.phpSerendipityAttack Blocked by Atomicorp344365
CVE-2026-11502JeecgBoot Third-Party Login ThirdLoginController.java HttpServletResponse.sendRedirect redirectJeecgBootAttack Blocked by Atomicorp340162 , 340163 , 340165 , 344365

Associated Atomicorp WAF Rules

RuleStatusBehavior
320007Activedisruptive (deny)
320464Activedisruptive (deny)
320465Activedisruptive (deny)
333140Activedisruptive (deny)
333141Activedisruptive (deny)
340023Activedisruptive (deny)
340087Activedisruptive (deny)
340095Activedisruptive (deny)
340099Activedisruptive (deny)
340147Activedisruptive (deny)
340148Activedisruptive (deny)
340162Activedisruptive (deny)
340163Activedisruptive (deny)
340165Activedisruptive (deny)
341099Activedisruptive (deny)
341256Activedisruptive (deny)
341266Activedisruptive (deny)
342259Activedisruptive (deny)
344360Activedisruptive (deny)
344361Activedisruptive (deny)
344363Activedisruptive (deny)
344365Activedisruptive (deny)
344370Activedisruptive (deny)
346755Activedisruptive (deny)
347198Activedisruptive (deny)
350147Activedisruptive (deny)
350148Activedisruptive (deny)
377360Activenon-disruptive (pass)
390145Activedisruptive (deny)
390500Activenon-disruptive (not available)
390501Activedisruptive (deny)
390703Activedisruptive (deny)
390716Activedisruptive (deny)
390726Activedisruptive (deny)
390727Activedisruptive (deny)
392301Activedisruptive (deny)
392647Activedisruptive (deny)
392648Activedisruptive (deny)
398005Activenon-disruptive (pass)

MITRE associates this CWE with the following attack-pattern entries. These taxonomy relationships are context, not Atomicorp coverage claims:

CAPEC-178 (opens in a new tab)