CVE-2026-55252
OpenRun: Redirect URL validation bypass using //host paths leads to Open Redirect
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
OpenRun is an open-source, self-hosted GitOps platform for deploying web apps and internal tools to Docker or Kubernetes. Prior to version 0.17.7, the restrictions on redirect URLs in openrun can be bypassed by attackers, leading to open redirect attacks. This issue has been patched in version 0.17.7.
| CWE | CWE-601 |
| Vendor | openrundev |
| Product | openrun |
| Published | Oct 1, 2026 |
Stay Ahead of the Next One
Get instant alerts for openrundev openrun
Be the first to know when new unknown vulnerabilities affecting openrundev openrun are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
openrundev / openrun
< 0.17.7