CVE-2020-26161: Octopus Deploy

Medium severity, CVSS 6.1. EPSS: 1.1% chance of exploitation in the next 30 days.

In Octopus Deploy through 2020.4.2, an attacker could redirect users to an external site via a modified HTTP Host header.

Affected products

  • Octopus Octopus Deploy: from 2019.8.2, up to and including 2020.4.2

Published 2020-10-26. Last modified 2026-06-17.