<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T11:16:05.852812+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2020-04820</id>
    <title>cnvd-2020-04820</title>
    <updated>2026-10-03T11:16:05.918101+00:00</updated>
    <content>cnvd-2020-04820</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2020-04820"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-36475</id>
    <title>EUVD-2026-36475</title>
    <updated>2026-10-03T11:16:05.918141+00:00</updated>
    <content>EUVD-2026-36475</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-36475"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2020-5233</id>
    <title>fkie_cve-2020-5233</title>
    <updated>2026-10-03T11:16:05.918156+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>OAuth2 Proxy before 5.0 has an open redirect vulnerability. Authentication tokens could be silently harvested by an attacker. This has been patched in version 5.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2020-5233"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-qqxw-m5fj-f7gv</id>
    <title>GHSA-qqxw-m5fj-f7gv — The pattern '/\domain.com' is not disallowed when redirecting, allowing for open redirect</title>
    <updated>2026-10-03T11:16:05.918186+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/oauth2-proxy/oauth2-proxy</p>
<p>### Impact
An open redirect vulnerability has been found in `oauth2_proxy`. Anyone who uses `oauth2_proxy` may potentially be impacted.</p>
<p>For a context [detectify] have an in depth blog post about the potential impact of an open redirect. Particularly see the OAuth section.</p>
<p>**tl;dr**: People's authentication tokens could be silently harvested by an attacker. e.g:
`facebook.com/oauth.php?clientid=123&amp;state=abc&amp;redirect_url=https://yourdomain.com/red.php?url%3dhttps://attacker.com/`</p>
<p>### Patches</p>
<p>@sauyon found the issue, and has submitted a patch.</p>
<p>```
diff --git a/oauthproxy.go b/oauthproxy.go
index 72ab580..f420df6 100644
--- a/oauthproxy.go
+++ b/oauthproxy.go
@@ -517,7 +517,7 @@ func (p *OAuthProxy) GetRedirect(req *http.Request) (redirect string, err error)
 // IsValidRedirect checks whether the redirect URL is whitelisted
 func (p *OAuthProxy) IsValidRedirect(redirect string) bool {
 	switch {
-	case strings.HasPrefix(redirect, "/") &amp;&amp; !strings.HasPrefix(redirect, "//"):
+	case strings.HasPrefix(redirect, "/") &amp;&amp; !strings.HasPrefix(redirect, "//") &amp;&amp; !strings.HasPrefix(redirect, "/\\"):
 		return true
 	case strings.HasPrefix(redirect, "http://") || strings.HasPrefix(redirect, "https://"):
 		redirectURL, err := url.Parse(redirect)
```</p>
<p>This patch will be applied to the next release, which is scheduled for when this is publicly disclosed.</p>
<p>### Workarounds</p>
<p>At this stage there is no work around.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-qqxw-m5fj-f7gv"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2020-5233</id>
    <title>gsd-2020-5233</title>
    <updated>2026-10-03T11:16:05.918229+00:00</updated>
    <content>gsd-2020-5233</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2020-5233"/>
  </entry>
</feed>
