๐Ÿ” CVE Alert

CVE-2026-82467

MEDIUM 4.7

Rodauth before 2.47.0 Open Redirect via Return-to Path

CVSS Score
4.7
EPSS Score
0.0%
EPSS Percentile
0th

Rodauth before 2.47.0 fails to validate protocol-relative return-to paths in confirm_password, login_return_to_requested_location, and two_factor_auth_return_to_requested_location features. Attackers can craft paths with leading double slashes that browsers resolve as protocol-relative URLs, redirecting authenticated users to attacker-controlled sites after login or password confirmation.

CWE CWE-601
Vendor jeremyevans
Product rodauth
Published Aug 29, 2026
Stay Ahead of the Next One

Get instant alerts for jeremyevans rodauth

Be the first to know when new medium vulnerabilities affecting jeremyevans rodauth are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None

Affected Versions

jeremyevans / rodauth
0 < 2.47.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/jeremyevans/rodauth/commit/295044a92e358479afdf84f905dd5efe89c39aea github.com: https://github.com/jeremyevans/rodauth/security/advisories/GHSA-h9m4-vm9w-h43m github.com: https://github.com/jeremyevans/rodauth vulncheck.com: https://www.vulncheck.com/advisories/rodauth-before-2.47.0-open-redirect-via-return-to-path

Credits

Joshua Rogers (AISLE Research)