Junglewise Threat Intelligence

CVE-2026-82467: Rodauth open redirect via protocol-relative return-to paths

CVE-2026-82467 · Severity: medium · CVSS 4.7 · Published 2026-08-29

Technologies: Rodauth.

Executive brief

Rodauth is a Ruby authentication framework used to handle user login and password confirmation. The framework failed to properly validate where users are redirected after login or password confirmation, allowing attackers to craft malicious URLs that redirect authenticated users to phishing sites while appearing to come from the legitimate login page.

Technical details

Rodauth before 2.47.0 contains an open redirect vulnerability in the confirm_password, login_return_to_requested_location, and two_factor_auth_return_to_requested_location features. The vulnerability stems from inadequate validation of protocol-relative paths (starting with //), which browsers interpret as URLs that adopt the current page's protocol. Attackers can craft return-to paths with leading double slashes to redirect authenticated users to attacker-controlled domains after successful authentication. The vulnerability requires no special privileges and is network-reachable; the victim must authenticate and be redirected. A fix was released in version 2.47.0 with new configuration methods (return_to_path_max_size and valid_return_to_path?) to validate redirect targets.

Affected products

  • Rodauth Rodauth before 2.47.0

Timeline

  • 2026-08-29: disclosed
  • 2026-08-23: patched: Fix released in version 2.47.0

References