{"id":"GHSA-8w27-c4vc-88q9","summary":"Concourse login flow has an open redirect issue","details":"### Impact\n\nAn attacker is able to craft and send a user a URL that will redirect the user from the Concourse web server to any other site. This could be used in a phishing attack to steal user's credentials.\n\n### Patches\n\nThis has been fixed in 8.2.3\n\n### Workarounds\n\nNone.\n\n### Exploit\n\nVulnerable code was in: https://github.com/concourse/concourse/blob/ea7b812e3a88fdd070f0faece874e8a2d4fbb31c/skymarshal/skyserver/skyserver.go#L162-L170\n\nThe issue stems from the underlying processing logic of Go's `url` package. Normally, `ParseRequestURI()` will eventually reach an internal `url.setPath()` function, where the URL will be decoded. However, if `RawPath` is not empty and `validEncoded(RawPath)` is true, and the decoded result equals `Path`, then return `RawPath` as is; otherwise, escape `Path` again, i.e., decode it again.\n\nIn other words, if the URL contains dangerous characters that should be escaped, such as backslashes (`\\`), then an extra decoding step will be performed. Therefore, `/%2Fexample.com` will be parsed as `//example.com`.\n\nOn vulnerable versions of Concourse, add `/sky/login?redirect_uri=/%252Fexample.com/\\` to your Concourse external URL, login as usual, and you should be redirected to `example.com` instead of your Concourse web server. The redirect happens after the login flow completes. No credentials are leaked.","aliases":["BIT-concourse-2026-49826","CVE-2026-49826","GO-2026-5866"],"modified":"2026-08-19T09:56:04.513841803Z","published":"2026-07-01T19:01:16Z","database_specific":{"cwe_ids":["CWE-601"],"severity":"LOW","github_reviewed":true,"github_reviewed_at":"2026-07-01T19:01:16Z","nvd_published_at":null},"references":[{"type":"WEB","url":"https://github.com/concourse/concourse/security/advisories/GHSA-8w27-c4vc-88q9"},{"type":"WEB","url":"https://github.com/concourse/concourse/commit/ac60be5f0435b6592f5a4fcc089050d72ad2452c"},{"type":"PACKAGE","url":"https://github.com/concourse/concourse"},{"type":"WEB","url":"https://github.com/concourse/concourse/releases/tag/v8.2.3"}],"affected":[{"package":{"name":"github.com/concourse/concourse","ecosystem":"Go","purl":"pkg:golang/github.com/concourse/concourse"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.6.1-0.20260526150512-ac60be5f0435"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-8w27-c4vc-88q9/GHSA-8w27-c4vc-88q9.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N"}]}