CVE-2026-83589: Red Hat Openshift Container Platform 4

Medium severity, CVSS 6.1. EPSS: 0.2% chance of exploitation in the next 30 days.

A flaw was found in oauth-proxy. The application fails to properly validate the destination redirect parameter (`rd`) during post-login redirection. A remote attacker can exploit this vulnerability by enticing a user to follow a specially crafted link, resulting in the user being redirected to an arbitrary external website after authenticating. This open redirect can be leveraged to conduct phishing attacks or credential theft.

Affected products

  • Red Hat Red Hat Openshift Container Platform 4
  • Red Hat Red Hat Openshift Container Platform 4.20: before 1790704224 (fixed in 1790704224)
  • Red Hat Red Hat Openshift Container Platform 4.21: before 1790706478 (fixed in 1790706478)
  • Red Hat Red Hat Openshift Container Platform 4.22: before 1790724885 (fixed in 1790724885)

Published 2026-10-01. Last modified 2026-10-07.