CVE-2019-19775: Zulip Server

Medium severity, CVSS 6.1. EPSS: 0.9% chance of exploitation in the next 30 days.

The image thumbnailing handler in Zulip Server versions 1.9.0 to before 2.0.8 allowed an open redirect that was visible to logged-in users.

Affected products

  • Zulip Zulip Server: from 1.9.0, before 2.0.8 (fixed in 2.0.8)

Published 2019-12-18. Last modified 2026-06-17.