CVE-2026-82467
Rodauth before 2.47.0 Open Redirect via Return-to Path
CVSS Score
4.7
EPSS Score
0.0%
EPSS Percentile
0th
Rodauth before 2.47.0 fails to validate protocol-relative return-to paths in confirm_password, login_return_to_requested_location, and two_factor_auth_return_to_requested_location features. Attackers can craft paths with leading double slashes that browsers resolve as protocol-relative URLs, redirecting authenticated users to attacker-controlled sites after login or password confirmation.
| CWE | CWE-601 |
| Vendor | jeremyevans |
| Product | rodauth |
| Published | Aug 29, 2026 |
Stay Ahead of the Next One
Get instant alerts for jeremyevans rodauth
Be the first to know when new medium vulnerabilities affecting jeremyevans rodauth are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None
Affected Versions
jeremyevans / rodauth
0 < 2.47.0
References
github.com: https://github.com/jeremyevans/rodauth/commit/295044a92e358479afdf84f905dd5efe89c39aea github.com: https://github.com/jeremyevans/rodauth/security/advisories/GHSA-h9m4-vm9w-h43m github.com: https://github.com/jeremyevans/rodauth vulncheck.com: https://www.vulncheck.com/advisories/rodauth-before-2.47.0-open-redirect-via-return-to-path
Credits
Joshua Rogers (AISLE Research)