CVE Feed

    Dashboard / CVE / CVE-2026-85676

    CVE-2026-85676

    Dub contains an open redirect vulnerability in the redir_url query parameter that is accepted on every short link without validation or domain allowlist enforcement. Attackers can append the redir_url parameter to any short link to redirect visitors to arbitrary external URLs through the trusted Dub domain, bypassing destination blacklists and potentially enabling phishing attacks with link cloaking enabled.

    Published:Sep 4, 2026
    Last Modified:Sep 7, 2026
    EPS:Sep 4, 2026
    EPSS Score:0.00242
    CVSS Score:4.3

    Affected Products

    Vendor
    Dub
    Product
    Dub

    Exploits

    No exploit reference

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High