CVE-2026-79662: Go Oauth Redirect Insufficient Path Validation

The redirect URL validation only compares URL scheme and host without validating the path component. An attacker could supply an arbitrary path on an allowed domain to capture OAuth codes or tokens via Referer headers, analytics scripts, or open redirects. Validate the full path or require exact URL matches.

Provally CuratedPublic repositoryMediumHigh confidenceVerifiedApache-2.0Go
greprules fetch cve-2026-79662-go-oauth-redirect-insufficient-path-validation --engine opengrep

Description

The redirect URL validation only compares URL scheme and host without validating the path component. An attacker could supply an arbitrary path on an allowed domain to capture OAuth codes or tokens via Referer headers, analytics scripts, or open redirects. Validate the full path or require exact URL matches.