Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-601

MITRE ↗

CWE-601

31
CRITICAL
165
HIGH
1,323
MEDIUM
78
LOW
1,655 CVEs · Page 4/34
6.1
CVE-2026-40181

React Router is a router for React. In versions 7.0.0 through 7.14.0 and 6.7.0 through 6.30.3, certain URLs passed to th

6.1
CVE-2026-41569

authentik is an open-source identity provider. Prior to version 2026.2.3, the WS-Federation provider validates the user-

6.1
CVE-2026-10856

A URL validation flaw in the MISP dashboard button widget allowed a crafted relative-looking URL to be accepted as a loc

6.1
CVE-2026-10861

An open redirect vulnerability existed in MISP UsersController::routeafterlogin() because the value stored in the pre_lo

6.1
CVE-2026-21826

HCL Digital Experience and HCL Digital Experience Compose could be susceptible to Host header injection.  An attacker ca

6.1
CVE-2026-47991

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by an Improper Redirect (Open Redire

6.1
CVE-2026-41008

Spring Security Authorization Server's authorization endpoint performs insufficient validation of the request_uri parame

6.1
CVE-2026-41706

Spring Security's CookieRequestCache and CookieServerRequestCache store the pre-authentication request URL in a browser

6.1
CVE-2026-45566

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, th

6.1
CVE-2026-50089

The Aqara IAM/SSO Gateway (gw-builder.aqara.com) provides an open redirect, which is an instance of "CWE-601: URL Redire

6.1
CVE-2026-44915

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache APISIX. The default configuration of cas-au

6.1
CVE-2026-54276

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, DigestAuthMiddleware ca

6.1
CVE-2026-44889

WebOb provides objects for HTTP requests and responses. Prior to 1.8.10, the normalization of the HTTP Location header d

6.1
CVE-2026-56326

Nuxt versions 4.0.0 before 4.4.7 and 3.x before 3.21.7 contain a server-side open redirect vulnerability in navigateTo t

6.1
CVE-2026-56697

Nuxt versions 4.0.0 before 4.4.7 and 3.x before 3.21.7 accept protocol-relative paths such as //evil.com in the reloadNu

6.1
CVE-2026-40080

Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Open Red

6.1
CVE-2026-58520

URL redirection to untrusted site ('open redirect') vulnerability in The Wikimedia Foundation Mediawiki - UrlShortener E

6.1
CVE-2026-25779

Gitea versions up to and including 1.25.4 allow redirect bypasses through raw or percent-encoded backslashes in redirect

6.1
CVE-2026-55590

CakePHP Authentication is an authentication plugin for CakePHP that can also be used in PSR-7 based applications. Prior

6.1
CVE-2026-55461

Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the user edit flow stores url()->previous() from the

6.1
CVE-2026-45065

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.4

6.1
CVE-2026-48000

Adobe Commerce is affected by an Improper Redirect (Open Redirect) vulnerability that could result in a Security feature

6.1
CVE-2026-48784

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.53, 6.4.4

6.1
CVE-2026-33213

Redash is a package for data visualization and sharing. From 5.0.2 to 26.3.0, the get_next_path() function in Redash's a

6.1
CVE-2026-61901

Joomla Extension - hikashop.com - Open redirect in Hikashop < 6.5.2 - The Joomla extension Hikashop is vulnerable to an

6.1
CVE-2026-8284

URL redirection to untrusted site ('open redirect') vulnerability in Universal Software Inc. FlexCity allows Input Data

6.1
CVE-2026-47002

Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: UI Framewo

6.1
CVE-2026-60685

Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations). Supported ver

6.1
CVE-2026-60842

Vulnerability in the Oracle Knowledge Management product of Oracle E-Business Suite (component: Search). Supported vers

6.1
CVE-2026-62444

Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations).

6.1
CVE-2026-64645

Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 thr

6.1
CVE-2026-53669

React Router is a router for React. Versions 6.0.0 through 7.17.0 are vulnerable to Open Redirtect through use of backsl

6.1
CVE-2026-14171

An unauthenticated remote attacker can abuse the improper validation of the post-login redirect of the web-UI to trick

6.1
CVE-2026-66414

Leantime 3.6.2 contains an open redirect vulnerability in the Login controller that allows unauthenticated attackers to

6.1
CVE-2026-66370

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in the HTML5 scrubber in rrrene html_sanitize_ex allow

6.1
CVE-2026-66829

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in the HTML5 scrubber in rrrene html_sanitize_ex allow

6.1
CVE-2026-73671

Saurus CMS Community Edition contains an unauthenticated open redirect vulnerability in the logout handling code in clas

6.1
CVE-2026-55087

Etherpad is a real-time collaborative editor. From 2.1.0 until 3.1.0, Etherpad uses the attacker-controlled x-proxy-path

6.1
CVE-2026-54770

WebOb provides objects for HTTP requests and responses. Prior to 1.8.11, Response._make_location_absolute() in src/webob

6.1
CVE-2026-47883

UrlHandlerFilter can be vulnerable to an open redirect when configured with very broadly matching patterns. The issue ap

6.1
CVE-2026-47887

A Spring MVC application that uses UrlFileNameViewController that is mapped with an end-of-path, and does not have a con

6.1
CVE-2026-59355

In versions of Spring Authorization Server 1.5.0 through 1.5.7, the authorization endpoint performs insufficient validat

6.1
CVE-2026-82464

pac4j-core before 6.5.6 contains an open redirect vulnerability in DefaultLogoutLogic.perform() that accepts backslash-p

5.9
CVE-2026-32235

Backstage is an open framework for building developer portals. Prior to 0.27.1, the experimental OIDC provider in @backs

5.9
CVE-2026-44833

Snipe-IT is an IT asset/license management system. Prior to 8.4.1, an open redirect vulnerability in Snipe-IT allows att

5.9
CVE-2026-55806

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Drupal Drupal core allows Content Spoofing. This is

5.9
CVE-2026-66773

A malicious or compromised OData service could disclose sensitive authentication information and inject untrusted data i

5.7
CVE-2026-44520

Docling-Graph turns documents into validated Pydantic objects, then builds a directed knowledge graph with explicit sema

5.7
CVE-2026-75628

Punk::OAuth2 versions before 0.03 for Perl allow an attacker-chosen off-site redirect after login because same_origin_pa

5.4
CVE-2025-61782

OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6.

Frequently Asked Questions

What is CWE-601?

CWE-601 (CWE-601) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-601?

There are 1,953 CVE records associated with CWE-601 in our database. Of these, 31 are critical severity, 165 are high severity, and 1323 are medium severity.

How can I protect against CWE-601 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-601 using AI-powered security agents.

Detect CWE-601 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-601 vulnerabilities across your infrastructure.

Get Started