CVE-2026-10837

Open redirection vulnerability due to insufficient validation of the X-Forwarded-Host HTTP header. An attacker could create manipulated links that, when opened by a victim, cause the victim to be redirected to domains controlled by the attacker, enabling phishing or deception attacks with limited impact on confidentiality and integrity.
CVSS

No CVSS.

Configurations

No configuration.

History

17 Jun 2026, 16:18

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-17 13:19

Updated : 2026-06-17 16:18


NVD link : CVE-2026-10837

Mitre link : CVE-2026-10837

CVE.ORG link : CVE-2026-10837


JSON object : View

Products Affected

No product.

CWE
CWE-601

URL Redirection to Untrusted Site ('Open Redirect')