CVE-2017-7266: Netflix Security Monkey
Medium severity, CVSS 6.1. EPSS: 1% chance of exploitation in the next 30 days.
Netflix Security Monkey before 0.8.0 has an Open Redirect. The logout functionality accepted the "next" parameter which then redirects to any domain irrespective of the Host header.
Affected products
- Netflix Security Monkey: up to and including 0.7.0
Published 2017-03-26. Last modified 2026-06-17.