Junglewise Threat Intelligence

CVE-2026-49826: Concourse CI open redirect in login flow

CVE-2026-49826 · Severity: medium · CVSS 4 · Published 2026-07-01

Vendors: Go.

Executive brief

Concourse CI, an open-source continuous integration tool, is vulnerable to an open redirect issue during its login process. An attacker can trick users into clicking a specially crafted link that, after a successful login, redirects them to a malicious external website. This technique is commonly used in phishing campaigns to deceive users into providing credentials to a fraudulent site that mimics the legitimate service.

Technical details

An open redirect vulnerability exists in Concourse CI's login flow due to improper handling of the 'redirect_uri' parameter. The root cause is related to how Go's 'url' package processes encoded characters; specifically, double-encoding or including backslashes can bypass path validation logic, causing a relative path like '/%2Fexample.com' to be interpreted as an absolute URL '//example.com'. An unauthenticated attacker can craft a URL that redirects a user to an arbitrary external site after they complete the login process. This issue is fixed in Concourse version 8.2.3.

Affected products

  • Concourse Concourse CI < 8.2.3

Timeline

  • 2026-05-27: disclosed
  • 2026-07-01: advisory: GitHub Advisory published
  • 2026-07-01: patched: Fix confirmed in version 8.2.3

References

Related threats