Project Subscriptions
No advisories yet.
Solution
No solution given by the vendor.
Workaround
There is no mitigation for this flaw. However, the risk is limited as the vulnerability only enables phishing — no OAuth tokens, authorization codes, or session credentials are exposed through the redirect.
Thu, 13 Aug 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat openshift Container Platform
|
|
| Vendors & Products |
Redhat openshift Container Platform
|
Wed, 12 Aug 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Tue, 11 Aug 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 11 Aug 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in the oauth-server component. This open redirect vulnerability occurs when the 'then' parameter in the grant approval handler is not properly validated. A remote attacker can craft a malicious URL that, when approved or denied by an authenticated user, redirects them to an attacker-controlled website. This could enable phishing attacks, potentially tricking users into revealing sensitive information. | |
| Title | Ose-oauth-server: oauth-server: open redirect vulnerability enables phishing via unvalidated parameter. | |
| First Time appeared |
Redhat
Redhat openshift |
|
| Weaknesses | CWE-601 | |
| CPEs | cpe:/a:redhat:openshift:4 | |
| Vendors & Products |
Redhat
Redhat openshift |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-08-11T15:56:06.058Z
Reserved: 2026-08-06T10:51:12.755Z
Link: CVE-2026-19078
Updated: 2026-08-11T15:55:58.352Z
Status : Awaiting Analysis
Published: 2026-08-11T16:17:31.620
Modified: 2026-08-14T19:07:46.080
Link: CVE-2026-19078
OpenCVE Enrichment
Updated: 2026-08-13T10:41:08Z