Junglewise Threat Intelligence

CVE-2026-66773: SAP python-pyodata open redirect in OData URL validation

CVE-2026-66773 · Severity: medium · CVSS 5.9 · Published 2026-08-11

Vendors: SAP.

Executive brief

SAP's python-pyodata library handles data retrieval from OData services and is used by applications to connect to enterprise data sources. A compromised or malicious OData service could exploit improper URL validation to redirect subsequent requests to untrusted locations, potentially stealing authentication credentials or injecting malicious data into the application.

Technical details

The vulnerability is an open redirect (CWE-601) in the python-pyodata library's handling of the OData `__next` URL parameter. The library fails to properly validate externally-supplied `__next` URLs, allowing a malicious or compromised OData service to redirect subsequent requests to attacker-controlled destinations. This requires low privileges and high attack complexity but does not require user interaction. An attacker can leverage this to harvest authentication tokens or inject malicious data. The fix is available in version 1.12.0 and later, which implements enhanced validation of OData `__next` URLs to prevent cross-origin redirects.

Affected products

  • SAP python-pyodata <1.12.0

Timeline

  • 2026-07-30: disclosed
  • 2026-08-11: patched: Fix available in version 1.12.0

References