CVE-2026-85676: Dub Open Redirect via Unrestricted redir_url Parameter

Published Sep 4, 2026
·
Updated

Dub contains an open redirect vulnerability in the redirurl query parameter that is accepted on every short link without validation or domain allowlist enforcement. Attackers can append the redirurl parameter to any short link to redirect visitors to arbitrary external URLs through the trusted Dub domain, bypassing destination blacklists and potentially enabling phishing attacks with link cloaking enabled.

Affected Software

1 affected component
Dub

Event History

Sep 4, 2026
CVE Published
via MITRE·02:32 PM
Data Sourced
via MITRE·02:32 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

Anyone who follows a Dub short link can be redirected to an attacker-controlled external site if the link includes a crafted redir_url parameter. The issue is particularly relevant where recipients trust the Dub domain or where link cloaking is enabled.

2

What does an attacker need to exploit it?

An attacker needs a Dub short link and can append an arbitrary redir_url query parameter. No authentication or other privileges are required, but a victim must follow the crafted link.

3

Are default deployments affected?

The redir_url parameter is described as being accepted on every short link without validation or domain allowlist enforcement. Based on the available information, exposure does not depend on a configured destination allowlist.

4

How can I determine whether an instance is affected?

Test a Dub short link with a redir_url query parameter pointing to an external domain and observe whether the visitor is redirected there. An affected instance permits the external redirect rather than validating or restricting the destination.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203