VYPR
Medium severity6.1NVD Advisory· Published Jul 9, 2026· Updated Jul 13, 2026

CVE-2026-55590

CVE-2026-55590

Description

CakePHP Authentication is an authentication plugin for CakePHP that can also be used in PSR-7 based applications. Prior to 2.11.1, 3.3.6, and 4.1.1, the getLoginRedirect() method contains a weakness to backslash bypasses that allows redirect targets with attacker-controlled hostnames through the redirect query string parameter. This issue is fixed in versions 2.11.1, 3.3.6, and 4.1.1.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
cakephp/authenticationPackagist
>= 3.0.0, < 3.3.63.3.6
cakephp/authenticationPackagist
>= 4.0.0, < 4.1.14.1.1
cakephp/authenticationPackagist
< 2.11.12.11.1

Affected products

2

Patches

Vulnerability mechanics

References

12

News mentions

0

No linked articles in our index yet.