Weaknesses of type CWE-601

1,187 results

Redirecionamento aberto para site não confiável

É quando uma aplicação redireciona o usuário para uma URL fornecida por ele (ou por um atacante) sem validação prévia. O navegador segue o redirecionamento automaticamente, levando a vítima para um site malicioso que pode clonar a interface legítima para roubar credenciais ou distribuir malware, com aparência de vir de um domínio confiável.

Example

Um link do tipo `https://banco.com/redirect?url=https://banco-falso.com` recebe a URL de destino como parâmetro e redireciona direto sem checagem. Atacante envia `https://banco.com/redirect?url=https://phishing.com` em email, e a vítima clica pensando estar acessando o banco.

How to mitigate

Valide sempre a URL de destino contra uma lista branca de domínios permitidos ou use URLs relativas. Se aceitar redirecionamentos dinâmicos, verifique que o host pertence ao seu domínio ou a uma lista explícita de parceiros confiáveis.

CVE-2026-55461MEDIUMSnipe-IT: Open Redirect After User EditEPSS 0.3%CVE-2025-30953MEDIUMWordPress WP Gravity Forms Salesforce plugin <= 1.4.7 - Open Redirection VulnerabilityEPSS 0.3%CVE-2025-47644MEDIUMWordPress Integrations of Zoho CRM with Elementor form plugin <= 1.0.8 - Open Redirection VulnerabilityEPSS 0.3%CVE-2025-30954MEDIUMWordPress WP Gravity Forms Constant Contact Plugin <= 1.1.0 - Open Redirection VulnerabilityEPSS 0.3%CVE-2025-47455MEDIUMWordPress Integration for WooCommerce and Salesforce plugin <= 1.7.5 - Open Redirection VulnerabilityEPSS 0.3%CVE-2025-47454MEDIUMWordPress WP Gravity Forms Dynamics CRM plugin <= 1.1.4 - Open Redirection VulnerabilityEPSS 0.3%CVE-2025-47456MEDIUMWordPress WP Gravity Forms Zendesk plugin <= 1.1.2 - Open Redirection VulnerabilityEPSS 0.3%CVE-2026-81036HIGHStalwart Mail Server through 0.16.19 Authorization Code Disclosure via Unvalidated OAuth redirect_uriEPSS 0.3%CVE-2026-31982MEDIUMOpen Redirect in SAML Single Sign-On in Guardian/CMC before 26.2.0EPSS 0.3%CVE-2026-33213MEDIUMRedash: Open redirect vulnerability in post-login redirect handlingEPSS 0.3%CVE-2025-71405MEDIUMgo-chi chi before v5.2.2 Open Redirect via RedirectSlashesEPSS 0.3%CVE-2024-55017HIGHAccount Takeover in Corezoid 6.6.0 in the OAuth2 implementation via an open redirect in the redirect_uri parameter allows attackers to interEPSS 0.3%CVE-2025-4328MEDIUMfp2952 spring-cloud-base HTTP Header MvcController.java sendBack redirectEPSS 0.3%CVE-2026-25198MEDIUMweb2py versions 2.27.1-stable+timestamp.2023.11.16.08.03.57 and prior contain an open redirect vulnerability. If this vulnerability is exploEPSS 0.3%CVE-2026-35258HIGHVulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 14.EPSS 0.3%CVE-2025-10355MEDIUMOpen redirection vulnerability in MOLGENIS EMX2EPSS 0.3%CVE-2024-0953MEDIUMWhen a user scans a QR Code with the QR Code Scanner feature, the user is not prompted before being navigated to the page specified in the cEPSS 0.3%CVE-2026-40037HIGHOpenClaw < 2026.3.31 - Unsafe Request Body Replay via fetchWithSsrFGuard Cross-Origin RedirectsEPSS 0.3%CVE-2026-21879MEDIUMKanboard vulnerable to Open Redirect via protocol-relative URLsEPSS 0.3%CVE-2026-88882CRITICALRenovate before 44.11.2 Credential Exfiltration via Link HeaderEPSS 0.3%