Junglewise Threat Intelligence

CVE-2026-45566: Roxy-WI open redirect in login flow via userinfo syntax bypass

CVE-2026-45566 · Severity: medium · CVSS 6.1 · Published 2026-06-10

Technologies: Roxy-WI. Vendors: Roxy-WI.

Executive brief

Roxy-WI, a management interface for web servers like Nginx and HAProxy, contains a security flaw in its login process. An attacker can trick users into visiting a malicious website by sending them a specially crafted link that appears to belong to the legitimate Roxy-WI server. This can be used in phishing attacks to steal user credentials or sensitive configuration data by mimicking the real application after the user logs in.

Technical details

An open redirect vulnerability (CWE-601) exists in Roxy-WI versions 8.2.6.4 and prior within the login flow. The application attempts to validate the 'next' parameter by checking for 'http://' or 'https://' substrings; however, it fails to account for the RFC 3986 userinfo syntax (e.g., @evil.com). When the application constructs the redirect URL as 'https://{request.host}{next_url}', a payload like '@evil.com' results in a URL that modern browsers interpret as having 'evil.com' as the authority. This allows a remote, unauthenticated attacker to redirect users to arbitrary external sites via a crafted URL. As of the advisory date, no official patches are available, though the advisory suggests implementing 'urllib.parse' for proper URL validation.

Affected products

  • Roxy-WI roxy-wi <= 8.2.6.4

Timeline

  • 2026-05-15: advisory: GitHub Security Advisory published
  • 2026-06-10: disclosed: CVE published to NVD

References

Related threats