VYPR

CVE-2026-53683

by Red Hat

CVEs (1)

  • CVE-2026-53683MedSep 2, 2026
    risk 0.28cvss 4.3epss

    reset_password.html parses query string parameters and uses the 'url' parameter as a redirection target (window.location = url) after password reset, optionally delayed by a 'delay' parameter. No validation or allowlisting is performed on url, enabling an attacker to redirect…