{"id":"CVE-2026-55590","aliases":["GHSA-hhpq-7wg4-36jm"],"url":"https://o3.security/vulnerability/CVE-2026-55590","summary":"CakePHP: Open redirect weakness via backslash bypass","details":"CakePHP Authentication is an authentication plugin for CakePHP that can also be used in PSR-7 based applications. Prior to 2.11.1, 3.3.6, and 4.1.1, the getLoginRedirect() method contains a weakness to backslash bypasses that allows redirect targets with attacker-controlled hostnames through the redirect query string parameter. This issue is fixed in versions 2.11.1, 3.3.6, and 4.1.1.","published":"2026-07-09T18:55:30.241Z","modified":"2026-08-12T03:51:17.172218092Z","cvss":null,"epss":{"score":0.00276,"percentile":0.20158,"asOf":"2026-08-23"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"cakephp/authentication","fixedVersion":"3.3.6"},{"ecosystem":"Packagist","name":"cakephp/authentication","fixedVersion":"4.1.1"},{"ecosystem":"Packagist","name":"cakephp/authentication","fixedVersion":"2.11.1"}],"fix":{"url":"https://github.com/cakephp/authentication/commit/1c1e29c7e8129cfbcae74558316ecd3ea50a8273","label":"cakephp/authentication@1c1e29c"},"references":[{"type":"WEB","url":"https://github.com/cakephp/authentication/releases/tag/2.11.1"},{"type":"WEB","url":"https://github.com/cakephp/authentication/releases/tag/3.3.6"},{"type":"WEB","url":"https://github.com/cakephp/authentication/releases/tag/4.1.1"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/55xxx/CVE-2026-55590.json"},{"type":"ADVISORY","url":"https://github.com/cakephp/authentication/security/advisories/GHSA-hhpq-7wg4-36jm"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55590"},{"type":"FIX","url":"https://github.com/cakephp/authentication/commit/1c1e29c7e8129cfbcae74558316ecd3ea50a8273"},{"type":"FIX","url":"https://github.com/cakephp/authentication/commit/df28ea4e712f1e5bd0e42be4a3c5c750ca50764d"},{"type":"FIX","url":"https://github.com/cakephp/authentication/commit/ee24bd48b9c3ef693dc9965de8f0cc8020a7052c"},{"type":"FIX","url":"https://github.com/cakephp/authentication/pull/795"},{"type":"FIX","url":"https://github.com/cakephp/authentication/pull/796"},{"type":"FIX","url":"https://github.com/cakephp/authentication/pull/799"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:17.172218092Z"}}