Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
🐍
🐍 PyPI
Not in CISA KEV
MEDIUM severity

CVE-2021-28125 — superset

MEDIUMFix: apache/superset@eb35b80

CVE-2021-28125 is a medium-severity (CVSS 6.1) Open Redirect vulnerability in superset. EPSS puts its 30-day exploitation probability at 64.0% (99th percentile). A fix is available for superset — see the affected versions and patch details below.

Open Redirect in Apache Superset

Also known asBIT-superset-2021-28125GHSA-pfwg-rxf4-97c3PYSEC-2021-128PYSEC-2026-3078
Published
Updated
Affected
2 pkgs
Patched
1 / 2
Exploits
None indexed
Exploitation data as of Oct 3, 2026 · OSV.dev, NVD, FIRST.org (EPSS)

EPSS Exploitation Probability

via FIRST.org ↗
64.0%probability of exploitation in next 30 days
High Risk0.00%
Lower risk than most CVEs99th percentile — riskier than 99% of all scored CVEsHighest risk
0.00%27.5%55.0%82.4%2.6%64.0%Jun 26Sep 26Oct 26

Probability of exploitation in the next 30 days, from FIRST.org EPSS.

How urgent is this, really

CVE-2021-28125 by exploitation likelihood (EPSS) against impact (CVSS). Outside the shaded patch-first corner.

Where this sits among everything scored

Of 385,386 CVEs with a current EPSS score, this one falls in the 50–90% band (highlighted). Counts from FIRST.org, log-scaled.

Real-World Exposure

2 pkgs affected
🐍superset🐍apache-superset

Real-time download stats are indexed for npm and PyPI packages. This vulnerability affects PyPI packages — download data is not available via public APIs for these ecosystems.

Description

Apache Superset up to and including 1.0.1 allowed for the creation of an external URL that could be malicious. By not checking user input for open redirects the URL shortener functionality would allow for a malicious user to create a short URL for a dashboard that could convince the user to click the link.

Affected Packages

2 total 1 fixed
EcosystemPackageVulnerable rangeFix
🐍PyPIsupersetall versionsNo fix
🐍PyPIapache-supersetall versions1.1.0pip install --upgrade 'apache-superset==1.1.0'

Affected Products

1 product · 1 configurations
Application
supersetapache
≤ 1.0.1
range

Detection & mitigation playbook

Open-source dependency
  1. Detect

    Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for superset, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version.

  2. Fix

    No patched version of superset has shipped for CVE-2021-28125 yet. Where your build allows, override or pin the dependency away from the vulnerable range, and apply any maintainer-recommended mitigation.

  3. Workarounds

    Stop reflecting attacker-controlled destinations: resolve every redirect target against an allowlist of paths or hosts you own, prefer a server-side key over a full URL in the request, and reject absolute URLs entirely where the flow only ever needs a relative one.

Frequently Asked Questions

Apache Superset up to and including 1.0.1 allowed for the creation of an external URL that could be malicious. By not checking user input for open redirects the URL shortener functionality would allow for a malicious user to create a short URL for a dashboard that could convince the user to click the link.
O3 Security · Impact-Aware SCA

Is CVE-2021-28125 in your dependencies?

Find it across PyPI, including transitive dependencies.

CVE-2021-28125: superset Open Redirect — Fixed in 1.1.0