CVE-2026-41479: Authlib Unvalidated Redirect Uri Error
Direct use of an unvalidated `redirect_uri` from a request payload in an error response class leads to an Open Redirect vulnerability. An attacker can manipulate the URL to silently redirect victims to untrusted domains. Validate the URI against the registered client via `check_redirect_uri` prior to use.
greprules fetch cve-2026-41479-authlib-unvalidated-redirect-uri-error --engine opengrepDescription
Direct use of an unvalidated `redirect_uri` from a request payload in an error response class leads to an Open Redirect vulnerability. An attacker can manipulate the URL to silently redirect victims to untrusted domains. Validate the URI against the registered client via `check_redirect_uri` prior to use.
Community feedback
0 rule-level signals from signed-in users.
- Useful reports
- 0
- Context false positives
- 0
- Metadata suggestions
- 0
Contextual precision
Aggregated from approved scan feedback. False-positive reports describe observed scan contexts, not a global rule verdict.
- Findings observed
- 0
- Projects
- 0
- Reporters
- 0
Precision details are collecting more signed-in reports before verdict counts or ratios are emphasized.
No approved finding verdicts yet.
No scan diagnostics reported yet.