Open Redirect - Vulnerability

Threat entity extracted from intelligence sources

Frequency
5
occurrences
First Seen
November 13, 2025
Last Seen
August 2, 2026

Open Redirect is a web vulnerability where an application accepts a user-supplied URL and redirects the user to another site, often without proper validation.

Open Redirect is a vulnerability tracked across 4 threat clusters and 5 intelligence report mentions on ThreatCluster. First observed November 13, 2025; most recent activity August 2, 2026.

Overview

Open Redirect is a web vulnerability where an application accepts a user-supplied URL and redirects the user to another site, often without proper validation. This can enable phishing, credential theft, or drive-by malware by steering users to attacker-controlled domains, and it remains a notable risk across consumer and enterprise software due to its ease of exploitation and broad prevalence.

Related Threat Clusters

Recent Intelligence Reports

  • Fedora 43 lemonldap-ng Update Open Redirect Fix CVE-2026 — Linuxsecurity · August 2, 2026
  • Snyk VulnBench JS 1.0: LLM Bug Repeatability — Snyk · June 29, 2026
  • Snyk VulnBench JS 1.0: LLM Bug Repeatability — Snyk · June 29, 2026
  • Your car’s web browser may be on the road to cyber ruin — Theregister · December 18, 2025
  • Three Critical Priority SAP Security Patches for November — Erp.Today · November 13, 2025

Frequently asked questions

What is Open Redirect?

Open Redirect is a web vulnerability where an application accepts a user-supplied URL and redirects the user to another site, often without proper validation.

Is Open Redirect still active?

The most recent intelligence report mentioning Open Redirect on ThreatCluster is dated August 2, 2026. Activity was first observed November 13, 2025, giving a tracked span from then to August 2, 2026.

What is Open Redirect associated with?

Across ThreatCluster reporting, Open Redirect most frequently co-occurs with Code Injection, Command Injection, Phishing, Privilege Escalation, Sql Injection, among 12 tracked related entities.

What are the latest developments involving Open Redirect?

The most significant recent cluster is “Critical Code Injection Vulnerability in SAP Solution Manager Disclosed” (7 articles · Updated December 9, 2025). Open Redirect appears across 4 threat clusters in total, listed above with sources.

How much reporting does ThreatCluster have on Open Redirect?

Open Redirect appears in 5 intelligence report mentions across 4 deduplicated threat clusters, aggregated from 17,000+ monitored sources.

CVSS v3.1 Breakdown