CVE-2026-34847: hoppscotch: Open redirect via `/enter?redirect=`
hoppscotch is an open source API development ecosystem. Prior to version 2026.3.0, the /enter page contains a DOM-based open redirect vulnerability. The redirect query parameter is directly used to construct a URL and redirect the user without proper validation. This issue has been patched in version 2026.3.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
hoppscotchto a version that resolves this vulnerability.Fixed in 2026.3.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-34847?
CVE-2026-34847 has a medium severity rating due to its potential for exploitation through open redirects.
How do I fix CVE-2026-34847?
To fix CVE-2026-34847, upgrade to version 2026.3.0 or later of Hoppscotch.
What version of Hoppscotch is affected by CVE-2026-34847?
Versions of Hoppscotch prior to 2026.3.0 are affected by CVE-2026-34847.
Can CVE-2026-34847 lead to phishing attacks?
Yes, CVE-2026-34847 can potentially be exploited for phishing attacks due to the open redirect vulnerability.
Is there a workaround for CVE-2026-34847 if I cannot upgrade?
There are no confirmed workarounds for CVE-2026-34847 other than upgrading to the secure version.