Weaknesses of type CWE-601

1,188 results

Redirecionamento aberto para site não confiável

É quando uma aplicação redireciona o usuário para uma URL fornecida por ele (ou por um atacante) sem validação prévia. O navegador segue o redirecionamento automaticamente, levando a vítima para um site malicioso que pode clonar a interface legítima para roubar credenciais ou distribuir malware, com aparência de vir de um domínio confiável.

Example

Um link do tipo `https://banco.com/redirect?url=https://banco-falso.com` recebe a URL de destino como parâmetro e redireciona direto sem checagem. Atacante envia `https://banco.com/redirect?url=https://phishing.com` em email, e a vítima clica pensando estar acessando o banco.

How to mitigate

Valide sempre a URL de destino contra uma lista branca de domínios permitidos ou use URLs relativas. Se aceitar redirecionamentos dinâmicos, verifique que o host pertence ao seu domínio ou a uma lista explícita de parceiros confiáveis.

CVE-2026-25149LOWQwik City Open Redirect via fixTrailingSlashEPSS 0.3%CVE-2025-2418MEDIUMOpen Redirect in TR7's Web Application FirewallEPSS 0.3%CVE-2026-45335MEDIUMWeGIA: Middleware whitelist bypass → open redirect via InternoControle.nextPageEPSS 0.3%CVE-2026-11502LOWJeecgBoot Third-Party Login ThirdLoginController.java HttpServletResponse.sendRedirect redirectEPSS 0.3%CVE-2026-96773MEDIUMIntelliants Subrion CMS Login Page login.php authorize redirectEPSS 0.3%CVE-2025-24868HIGHOpen Redirect Vulnerability in SAP HANA extended application services, advanced model (User Account and Authentication Services)EPSS 0.2%CVE-2025-46553LOW@misskey-dev/summaly Redirect Filter BypassEPSS 0.2%CVE-2026-77609MEDIUMSemantic MediaWiki has an open redirect in Special:URIResolverEPSS 0.2%CVE-2025-6286MEDIUMPHPGurukul COVID19 Testing Management System search-report-result.php redirectEPSS 0.2%CVE-2024-21684LOWThere is a low severity open redirect vulnerability within affected versions of Bitbucket Data Center. Versions of Bitbucket DC from 8.0.0 tEPSS 0.2%CVE-2025-57879MEDIUMBUG-000171009 - URL manipulation vulnerability in Portal for ArcGIS.EPSS 0.2%CVE-2025-20355MEDIUMCisco Catalyst Center Software HTTP Open Redirect VulnerabilityEPSS 0.2%CVE-2025-57878MEDIUMBUG-000174149 - The Portal for ArcGIS has an unvalidated redirect.EPSS 0.2%CVE-2025-57872MEDIUMBUG-000174150 - Unvalidated redirect in Portal for ArcGIS.EPSS 0.2%CVE-2026-44833MEDIUMSnipe-IT: Open redirect vulnerabilityEPSS 0.2%CVE-2025-36016MEDIUMIBM Process Mining HTTP open redirectEPSS 0.2%CVE-2026-34283MEDIUMVulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Identity Console). Supported versions that areEPSS 0.2%CVE-2026-34284MEDIUMVulnerability in the Oracle Business Process Management Suite product of Oracle Fusion Middleware (component: Human workflow 11g+). SupportEPSS 0.2%CVE-2025-64250MEDIUMWordPress Directorist plugin <= 8.6.6 - Open Redirection vulnerabilityEPSS 0.2%CVE-2026-62444MEDIUMVulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations). Supported versions tEPSS 0.2%