cakephp/authentication
Authentication plugin for CakePHP. Can also be used in PSR7 based applications.
Activity
- Latest release
- 1mo ago
- Total releases
- 77
- Cadence
- ~23 days
- Last 12 months
- 14
Reach
- Stars
- 118
Details
- License
- MIT
- First release
- Dec 27, 2016
| Version | Released | |
|---|---|---|
2.11.3
patch
| ||
2.11.2
patch
| ||
3.3.7
patch
| ||
4.2.1
patch
|
4.2.1
patch
Dependencies (7)
Changelog
Compare changes
|
|
2.11.1
patch
| ||
4.2.0
minor
| ||
3.3.6
patch
| ||
4.1.1
patch
| ||
4.1.0
minor
1 CVE
CVE-2026-55590
GHSA-hhpq-7wg4-36jm
Jun 17, 2026
CakePHP Authentication: Open redirect weakness via backslash bypass
Medium
Network
Low
None
ImpactThe Patches2.11.1, 3.3.6 and 4.1.1 contain a fix for this issue. WorkaroundsIf you are unable to upgrade, you should consider adding application validation to the redirect query string parameter to mitigate this vulnerability. Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
+ 59 more Show less
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
4.0.0
4.0.1
4.1.0
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.0-rc5
1.0.0-rc6
1.0.0-rc7
1.0.0-rc8
1.0.0-rc9
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.10.0
2.10.1
2.10.2
2.11.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.9.0
Fixed in
2.11.1
3.3.6
4.1.1
References
Updated Aug 14, 2026 · Source: OSV.dev | ||
4.0.1
patch
1 CVE
CVE-2026-55590
GHSA-hhpq-7wg4-36jm
Jun 17, 2026
CakePHP Authentication: Open redirect weakness via backslash bypass
Medium
Network
Low
None
ImpactThe Patches2.11.1, 3.3.6 and 4.1.1 contain a fix for this issue. WorkaroundsIf you are unable to upgrade, you should consider adding application validation to the redirect query string parameter to mitigate this vulnerability. Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
+ 59 more Show less
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
4.0.0
4.0.1
4.1.0
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.0-rc5
1.0.0-rc6
1.0.0-rc7
1.0.0-rc8
1.0.0-rc9
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.10.0
2.10.1
2.10.2
2.11.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.9.0
Fixed in
2.11.1
3.3.6
4.1.1
References
Updated Aug 14, 2026 · Source: OSV.dev | ||
4.0.0
major
1 CVE
CVE-2026-55590
GHSA-hhpq-7wg4-36jm
Jun 17, 2026
CakePHP Authentication: Open redirect weakness via backslash bypass
Medium
Network
Low
None
ImpactThe Patches2.11.1, 3.3.6 and 4.1.1 contain a fix for this issue. WorkaroundsIf you are unable to upgrade, you should consider adding application validation to the redirect query string parameter to mitigate this vulnerability. Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
+ 59 more Show less
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
4.0.0
4.0.1
4.1.0
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.0-rc5
1.0.0-rc6
1.0.0-rc7
1.0.0-rc8
1.0.0-rc9
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.10.0
2.10.1
2.10.2
2.11.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.9.0
Fixed in
2.11.1
3.3.6
4.1.1
References
Updated Aug 14, 2026 · Source: OSV.dev | ||
3.3.5
patch
1 CVE
CVE-2026-55590
GHSA-hhpq-7wg4-36jm
Jun 17, 2026
CakePHP Authentication: Open redirect weakness via backslash bypass
Medium
Network
Low
None
ImpactThe Patches2.11.1, 3.3.6 and 4.1.1 contain a fix for this issue. WorkaroundsIf you are unable to upgrade, you should consider adding application validation to the redirect query string parameter to mitigate this vulnerability. Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
+ 59 more Show less
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
4.0.0
4.0.1
4.1.0
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.0-rc5
1.0.0-rc6
1.0.0-rc7
1.0.0-rc8
1.0.0-rc9
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.10.0
2.10.1
2.10.2
2.11.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.9.0
Fixed in
2.11.1
3.3.6
4.1.1
References
Updated Aug 14, 2026 · Source: OSV.dev | ||
3.3.4
patch
1 CVE
CVE-2026-55590
GHSA-hhpq-7wg4-36jm
Jun 17, 2026
CakePHP Authentication: Open redirect weakness via backslash bypass
Medium
Network
Low
None
ImpactThe Patches2.11.1, 3.3.6 and 4.1.1 contain a fix for this issue. WorkaroundsIf you are unable to upgrade, you should consider adding application validation to the redirect query string parameter to mitigate this vulnerability. Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
+ 59 more Show less
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
4.0.0
4.0.1
4.1.0
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.0-rc5
1.0.0-rc6
1.0.0-rc7
1.0.0-rc8
1.0.0-rc9
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.10.0
2.10.1
2.10.2
2.11.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.9.0
Fixed in
2.11.1
3.3.6
4.1.1
References
Updated Aug 14, 2026 · Source: OSV.dev | ||
3.3.3
patch
1 CVE
CVE-2026-55590
GHSA-hhpq-7wg4-36jm
Jun 17, 2026
CakePHP Authentication: Open redirect weakness via backslash bypass
Medium
Network
Low
None
ImpactThe Patches2.11.1, 3.3.6 and 4.1.1 contain a fix for this issue. WorkaroundsIf you are unable to upgrade, you should consider adding application validation to the redirect query string parameter to mitigate this vulnerability. Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
+ 59 more Show less
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
4.0.0
4.0.1
4.1.0
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.0-rc5
1.0.0-rc6
1.0.0-rc7
1.0.0-rc8
1.0.0-rc9
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.10.0
2.10.1
2.10.2
2.11.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.9.0
Fixed in
2.11.1
3.3.6
4.1.1
References
Updated Aug 14, 2026 · Source: OSV.dev | ||
3.3.2
patch
1 CVE
CVE-2026-55590
GHSA-hhpq-7wg4-36jm
Jun 17, 2026
CakePHP Authentication: Open redirect weakness via backslash bypass
Medium
Network
Low
None
ImpactThe Patches2.11.1, 3.3.6 and 4.1.1 contain a fix for this issue. WorkaroundsIf you are unable to upgrade, you should consider adding application validation to the redirect query string parameter to mitigate this vulnerability. Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
+ 59 more Show less
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
4.0.0
4.0.1
4.1.0
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.0-rc5
1.0.0-rc6
1.0.0-rc7
1.0.0-rc8
1.0.0-rc9
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.10.0
2.10.1
2.10.2
2.11.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.9.0
Fixed in
2.11.1
3.3.6
4.1.1
References
Updated Aug 14, 2026 · Source: OSV.dev | ||
3.3.1
patch
1 CVE
CVE-2026-55590
GHSA-hhpq-7wg4-36jm
Jun 17, 2026
CakePHP Authentication: Open redirect weakness via backslash bypass
Medium
Network
Low
None
ImpactThe Patches2.11.1, 3.3.6 and 4.1.1 contain a fix for this issue. WorkaroundsIf you are unable to upgrade, you should consider adding application validation to the redirect query string parameter to mitigate this vulnerability. Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
+ 59 more Show less
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
4.0.0
4.0.1
4.1.0
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.0-rc5
1.0.0-rc6
1.0.0-rc7
1.0.0-rc8
1.0.0-rc9
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.10.0
2.10.1
2.10.2
2.11.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.9.0
Fixed in
2.11.1
3.3.6
4.1.1
References
Updated Aug 14, 2026 · Source: OSV.dev | ||
3.3.0
minor
1 CVE
CVE-2026-55590
GHSA-hhpq-7wg4-36jm
Jun 17, 2026
CakePHP Authentication: Open redirect weakness via backslash bypass
Medium
Network
Low
None
ImpactThe Patches2.11.1, 3.3.6 and 4.1.1 contain a fix for this issue. WorkaroundsIf you are unable to upgrade, you should consider adding application validation to the redirect query string parameter to mitigate this vulnerability. Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
+ 59 more Show less
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
4.0.0
4.0.1
4.1.0
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.0-rc5
1.0.0-rc6
1.0.0-rc7
1.0.0-rc8
1.0.0-rc9
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.10.0
2.10.1
2.10.2
2.11.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.9.0
Fixed in
2.11.1
3.3.6
4.1.1
References
Updated Aug 14, 2026 · Source: OSV.dev | ||
3.2.5
patch
1 CVE
CVE-2026-55590
GHSA-hhpq-7wg4-36jm
Jun 17, 2026
CakePHP Authentication: Open redirect weakness via backslash bypass
Medium
Network
Low
None
ImpactThe Patches2.11.1, 3.3.6 and 4.1.1 contain a fix for this issue. WorkaroundsIf you are unable to upgrade, you should consider adding application validation to the redirect query string parameter to mitigate this vulnerability. Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
+ 59 more Show less
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
4.0.0
4.0.1
4.1.0
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.0-rc5
1.0.0-rc6
1.0.0-rc7
1.0.0-rc8
1.0.0-rc9
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.10.0
2.10.1
2.10.2
2.11.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.9.0
Fixed in
2.11.1
3.3.6
4.1.1
References
Updated Aug 14, 2026 · Source: OSV.dev | ||
3.2.4
patch
1 CVE
CVE-2026-55590
GHSA-hhpq-7wg4-36jm
Jun 17, 2026
CakePHP Authentication: Open redirect weakness via backslash bypass
Medium
Network
Low
None
ImpactThe Patches2.11.1, 3.3.6 and 4.1.1 contain a fix for this issue. WorkaroundsIf you are unable to upgrade, you should consider adding application validation to the redirect query string parameter to mitigate this vulnerability. Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
+ 59 more Show less
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
4.0.0
4.0.1
4.1.0
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.0-rc5
1.0.0-rc6
1.0.0-rc7
1.0.0-rc8
1.0.0-rc9
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.10.0
2.10.1
2.10.2
2.11.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.9.0
Fixed in
2.11.1
3.3.6
4.1.1
References
Updated Aug 14, 2026 · Source: OSV.dev | ||
3.2.3
patch
1 CVE
CVE-2026-55590
GHSA-hhpq-7wg4-36jm
Jun 17, 2026
CakePHP Authentication: Open redirect weakness via backslash bypass
Medium
Network
Low
None
ImpactThe Patches2.11.1, 3.3.6 and 4.1.1 contain a fix for this issue. WorkaroundsIf you are unable to upgrade, you should consider adding application validation to the redirect query string parameter to mitigate this vulnerability. Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
+ 59 more Show less
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
4.0.0
4.0.1
4.1.0
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.0-rc5
1.0.0-rc6
1.0.0-rc7
1.0.0-rc8
1.0.0-rc9
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.10.0
2.10.1
2.10.2
2.11.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.9.0
Fixed in
2.11.1
3.3.6
4.1.1
References
Updated Aug 14, 2026 · Source: OSV.dev | ||
3.2.2
patch
1 CVE
CVE-2026-55590
GHSA-hhpq-7wg4-36jm
Jun 17, 2026
CakePHP Authentication: Open redirect weakness via backslash bypass
Medium
Network
Low
None
ImpactThe Patches2.11.1, 3.3.6 and 4.1.1 contain a fix for this issue. WorkaroundsIf you are unable to upgrade, you should consider adding application validation to the redirect query string parameter to mitigate this vulnerability. Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
+ 59 more Show less
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
4.0.0
4.0.1
4.1.0
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.0-rc5
1.0.0-rc6
1.0.0-rc7
1.0.0-rc8
1.0.0-rc9
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.10.0
2.10.1
2.10.2
2.11.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.9.0
Fixed in
2.11.1
3.3.6
4.1.1
References
Updated Aug 14, 2026 · Source: OSV.dev | ||
3.2.1
patch
1 CVE
CVE-2026-55590
GHSA-hhpq-7wg4-36jm
Jun 17, 2026
CakePHP Authentication: Open redirect weakness via backslash bypass
Medium
Network
Low
None
ImpactThe Patches2.11.1, 3.3.6 and 4.1.1 contain a fix for this issue. WorkaroundsIf you are unable to upgrade, you should consider adding application validation to the redirect query string parameter to mitigate this vulnerability. Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
+ 59 more Show less
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
4.0.0
4.0.1
4.1.0
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.0-rc5
1.0.0-rc6
1.0.0-rc7
1.0.0-rc8
1.0.0-rc9
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.10.0
2.10.1
2.10.2
2.11.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.9.0
Fixed in
2.11.1
3.3.6
4.1.1
References
Updated Aug 14, 2026 · Source: OSV.dev | ||
2.11.0
minor
1 CVE
CVE-2026-55590
GHSA-hhpq-7wg4-36jm
Jun 17, 2026
CakePHP Authentication: Open redirect weakness via backslash bypass
Medium
Network
Low
None
ImpactThe Patches2.11.1, 3.3.6 and 4.1.1 contain a fix for this issue. WorkaroundsIf you are unable to upgrade, you should consider adding application validation to the redirect query string parameter to mitigate this vulnerability. Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
+ 59 more Show less
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
4.0.0
4.0.1
4.1.0
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.0-rc5
1.0.0-rc6
1.0.0-rc7
1.0.0-rc8
1.0.0-rc9
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.10.0
2.10.1
2.10.2
2.11.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.9.0
Fixed in
2.11.1
3.3.6
4.1.1
References
Updated Aug 14, 2026 · Source: OSV.dev | ||
3.2.0
minor
1 CVE
CVE-2026-55590
GHSA-hhpq-7wg4-36jm
Jun 17, 2026
CakePHP Authentication: Open redirect weakness via backslash bypass
Medium
Network
Low
None
ImpactThe Patches2.11.1, 3.3.6 and 4.1.1 contain a fix for this issue. WorkaroundsIf you are unable to upgrade, you should consider adding application validation to the redirect query string parameter to mitigate this vulnerability. Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
+ 59 more Show less
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
4.0.0
4.0.1
4.1.0
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.0-rc5
1.0.0-rc6
1.0.0-rc7
1.0.0-rc8
1.0.0-rc9
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.10.0
2.10.1
2.10.2
2.11.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.9.0
Fixed in
2.11.1
3.3.6
4.1.1
References
Updated Aug 14, 2026 · Source: OSV.dev | ||
3.1.1
patch
1 CVE
CVE-2026-55590
GHSA-hhpq-7wg4-36jm
Jun 17, 2026
CakePHP Authentication: Open redirect weakness via backslash bypass
Medium
Network
Low
None
ImpactThe Patches2.11.1, 3.3.6 and 4.1.1 contain a fix for this issue. WorkaroundsIf you are unable to upgrade, you should consider adding application validation to the redirect query string parameter to mitigate this vulnerability. Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
+ 59 more Show less
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
4.0.0
4.0.1
4.1.0
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.0-rc5
1.0.0-rc6
1.0.0-rc7
1.0.0-rc8
1.0.0-rc9
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.10.0
2.10.1
2.10.2
2.11.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.9.0
Fixed in
2.11.1
3.3.6
4.1.1
References
Updated Aug 14, 2026 · Source: OSV.dev | ||
3.1.0
minor
1 CVE
CVE-2026-55590
GHSA-hhpq-7wg4-36jm
Jun 17, 2026
CakePHP Authentication: Open redirect weakness via backslash bypass
Medium
Network
Low
None
ImpactThe Patches2.11.1, 3.3.6 and 4.1.1 contain a fix for this issue. WorkaroundsIf you are unable to upgrade, you should consider adding application validation to the redirect query string parameter to mitigate this vulnerability. Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
+ 59 more Show less
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
4.0.0
4.0.1
4.1.0
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.0-rc5
1.0.0-rc6
1.0.0-rc7
1.0.0-rc8
1.0.0-rc9
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.10.0
2.10.1
2.10.2
2.11.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.9.0
Fixed in
2.11.1
3.3.6
4.1.1
References
Updated Aug 14, 2026 · Source: OSV.dev | ||
3.0.3
patch
1 CVE
CVE-2026-55590
GHSA-hhpq-7wg4-36jm
Jun 17, 2026
CakePHP Authentication: Open redirect weakness via backslash bypass
Medium
Network
Low
None
ImpactThe Patches2.11.1, 3.3.6 and 4.1.1 contain a fix for this issue. WorkaroundsIf you are unable to upgrade, you should consider adding application validation to the redirect query string parameter to mitigate this vulnerability. Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
+ 59 more Show less
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
4.0.0
4.0.1
4.1.0
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.0-rc5
1.0.0-rc6
1.0.0-rc7
1.0.0-rc8
1.0.0-rc9
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.10.0
2.10.1
2.10.2
2.11.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.9.0
Fixed in
2.11.1
3.3.6
4.1.1
References
Updated Aug 14, 2026 · Source: OSV.dev | ||
2.10.2
patch
1 CVE
CVE-2026-55590
GHSA-hhpq-7wg4-36jm
Jun 17, 2026
CakePHP Authentication: Open redirect weakness via backslash bypass
Medium
Network
Low
None
ImpactThe Patches2.11.1, 3.3.6 and 4.1.1 contain a fix for this issue. WorkaroundsIf you are unable to upgrade, you should consider adding application validation to the redirect query string parameter to mitigate this vulnerability. Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
+ 59 more Show less
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
4.0.0
4.0.1
4.1.0
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.0-rc5
1.0.0-rc6
1.0.0-rc7
1.0.0-rc8
1.0.0-rc9
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.10.0
2.10.1
2.10.2
2.11.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.9.0
Fixed in
2.11.1
3.3.6
4.1.1
References
Updated Aug 14, 2026 · Source: OSV.dev | ||
3.0.2
patch
1 CVE
CVE-2026-55590
GHSA-hhpq-7wg4-36jm
Jun 17, 2026
CakePHP Authentication: Open redirect weakness via backslash bypass
Medium
Network
Low
None
ImpactThe Patches2.11.1, 3.3.6 and 4.1.1 contain a fix for this issue. WorkaroundsIf you are unable to upgrade, you should consider adding application validation to the redirect query string parameter to mitigate this vulnerability. Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
+ 59 more Show less
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
4.0.0
4.0.1
4.1.0
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.0-rc5
1.0.0-rc6
1.0.0-rc7
1.0.0-rc8
1.0.0-rc9
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.10.0
2.10.1
2.10.2
2.11.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.9.0
Fixed in
2.11.1
3.3.6
4.1.1
References
Updated Aug 14, 2026 · Source: OSV.dev | ||
3.0.1
major
1 CVE
CVE-2026-55590
GHSA-hhpq-7wg4-36jm
Jun 17, 2026
CakePHP Authentication: Open redirect weakness via backslash bypass
Medium
Network
Low
None
ImpactThe Patches2.11.1, 3.3.6 and 4.1.1 contain a fix for this issue. WorkaroundsIf you are unable to upgrade, you should consider adding application validation to the redirect query string parameter to mitigate this vulnerability. Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
+ 59 more Show less
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
4.0.0
4.0.1
4.1.0
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.0-rc5
1.0.0-rc6
1.0.0-rc7
1.0.0-rc8
1.0.0-rc9
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.10.0
2.10.1
2.10.2
2.11.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.9.0
Fixed in
2.11.1
3.3.6
4.1.1
References
Updated Aug 14, 2026 · Source: OSV.dev | ||
2.10.1
patch
1 CVE
CVE-2026-55590
GHSA-hhpq-7wg4-36jm
Jun 17, 2026
CakePHP Authentication: Open redirect weakness via backslash bypass
Medium
Network
Low
None
ImpactThe Patches2.11.1, 3.3.6 and 4.1.1 contain a fix for this issue. WorkaroundsIf you are unable to upgrade, you should consider adding application validation to the redirect query string parameter to mitigate this vulnerability. Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
+ 59 more Show less
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
4.0.0
4.0.1
4.1.0
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.0-rc5
1.0.0-rc6
1.0.0-rc7
1.0.0-rc8
1.0.0-rc9
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.10.0
2.10.1
2.10.2
2.11.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.9.0
Fixed in
2.11.1
3.3.6
4.1.1
References
Updated Aug 14, 2026 · Source: OSV.dev | ||
2.10.0
minor
1 CVE
CVE-2026-55590
GHSA-hhpq-7wg4-36jm
Jun 17, 2026
CakePHP Authentication: Open redirect weakness via backslash bypass
Medium
Network
Low
None
ImpactThe Patches2.11.1, 3.3.6 and 4.1.1 contain a fix for this issue. WorkaroundsIf you are unable to upgrade, you should consider adding application validation to the redirect query string parameter to mitigate this vulnerability. Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
+ 59 more Show less
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
4.0.0
4.0.1
4.1.0
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.0-rc5
1.0.0-rc6
1.0.0-rc7
1.0.0-rc8
1.0.0-rc9
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.10.0
2.10.1
2.10.2
2.11.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.9.0
Fixed in
2.11.1
3.3.6
4.1.1
References
Updated Aug 14, 2026 · Source: OSV.dev | ||
2.9.0
minor
1 CVE
CVE-2026-55590
GHSA-hhpq-7wg4-36jm
Jun 17, 2026
CakePHP Authentication: Open redirect weakness via backslash bypass
Medium
Network
Low
None
ImpactThe Patches2.11.1, 3.3.6 and 4.1.1 contain a fix for this issue. WorkaroundsIf you are unable to upgrade, you should consider adding application validation to the redirect query string parameter to mitigate this vulnerability. Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
+ 59 more Show less
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
4.0.0
4.0.1
4.1.0
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.0-rc5
1.0.0-rc6
1.0.0-rc7
1.0.0-rc8
1.0.0-rc9
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.10.0
2.10.1
2.10.2
2.11.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.9.0
Fixed in
2.11.1
3.3.6
4.1.1
References
Updated Aug 14, 2026 · Source: OSV.dev | ||
2.8.0
minor
1 CVE
CVE-2026-55590
GHSA-hhpq-7wg4-36jm
Jun 17, 2026
CakePHP Authentication: Open redirect weakness via backslash bypass
Medium
Network
Low
None
ImpactThe Patches2.11.1, 3.3.6 and 4.1.1 contain a fix for this issue. WorkaroundsIf you are unable to upgrade, you should consider adding application validation to the redirect query string parameter to mitigate this vulnerability. Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
+ 59 more Show less
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
4.0.0
4.0.1
4.1.0
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.0-rc5
1.0.0-rc6
1.0.0-rc7
1.0.0-rc8
1.0.0-rc9
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.10.0
2.10.1
2.10.2
2.11.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.9.0
Fixed in
2.11.1
3.3.6
4.1.1
References
Updated Aug 14, 2026 · Source: OSV.dev | ||
2.7.0
minor
1 CVE
CVE-2026-55590
GHSA-hhpq-7wg4-36jm
Jun 17, 2026
CakePHP Authentication: Open redirect weakness via backslash bypass
Medium
Network
Low
None
ImpactThe Patches2.11.1, 3.3.6 and 4.1.1 contain a fix for this issue. WorkaroundsIf you are unable to upgrade, you should consider adding application validation to the redirect query string parameter to mitigate this vulnerability. Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
+ 59 more Show less
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
4.0.0
4.0.1
4.1.0
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.0-rc5
1.0.0-rc6
1.0.0-rc7
1.0.0-rc8
1.0.0-rc9
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.10.0
2.10.1
2.10.2
2.11.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.9.0
Fixed in
2.11.1
3.3.6
4.1.1
References
Updated Aug 14, 2026 · Source: OSV.dev | ||
2.6.2
patch
1 CVE
CVE-2026-55590
GHSA-hhpq-7wg4-36jm
Jun 17, 2026
CakePHP Authentication: Open redirect weakness via backslash bypass
Medium
Network
Low
None
ImpactThe Patches2.11.1, 3.3.6 and 4.1.1 contain a fix for this issue. WorkaroundsIf you are unable to upgrade, you should consider adding application validation to the redirect query string parameter to mitigate this vulnerability. Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
+ 59 more Show less
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
4.0.0
4.0.1
4.1.0
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.0-rc5
1.0.0-rc6
1.0.0-rc7
1.0.0-rc8
1.0.0-rc9
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.10.0
2.10.1
2.10.2
2.11.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.9.0
Fixed in
2.11.1
3.3.6
4.1.1
References
Updated Aug 14, 2026 · Source: OSV.dev | ||
2.6.1
patch
1 CVE
CVE-2026-55590
GHSA-hhpq-7wg4-36jm
Jun 17, 2026
CakePHP Authentication: Open redirect weakness via backslash bypass
Medium
Network
Low
None
ImpactThe Patches2.11.1, 3.3.6 and 4.1.1 contain a fix for this issue. WorkaroundsIf you are unable to upgrade, you should consider adding application validation to the redirect query string parameter to mitigate this vulnerability. Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
+ 59 more Show less
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
4.0.0
4.0.1
4.1.0
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.0-rc5
1.0.0-rc6
1.0.0-rc7
1.0.0-rc8
1.0.0-rc9
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.10.0
2.10.1
2.10.2
2.11.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.9.0
Fixed in
2.11.1
3.3.6
4.1.1
References
Updated Aug 14, 2026 · Source: OSV.dev | ||
2.6.0
minor
1 CVE
CVE-2026-55590
GHSA-hhpq-7wg4-36jm
Jun 17, 2026
CakePHP Authentication: Open redirect weakness via backslash bypass
Medium
Network
Low
None
ImpactThe Patches2.11.1, 3.3.6 and 4.1.1 contain a fix for this issue. WorkaroundsIf you are unable to upgrade, you should consider adding application validation to the redirect query string parameter to mitigate this vulnerability. Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
+ 59 more Show less
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
4.0.0
4.0.1
4.1.0
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.0-rc5
1.0.0-rc6
1.0.0-rc7
1.0.0-rc8
1.0.0-rc9
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.10.0
2.10.1
2.10.2
2.11.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.9.0
Fixed in
2.11.1
3.3.6
4.1.1
References
Updated Aug 14, 2026 · Source: OSV.dev | ||
2.5.0
minor
1 CVE
CVE-2026-55590
GHSA-hhpq-7wg4-36jm
Jun 17, 2026
CakePHP Authentication: Open redirect weakness via backslash bypass
Medium
Network
Low
None
ImpactThe Patches2.11.1, 3.3.6 and 4.1.1 contain a fix for this issue. WorkaroundsIf you are unable to upgrade, you should consider adding application validation to the redirect query string parameter to mitigate this vulnerability. Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
+ 59 more Show less
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
4.0.0
4.0.1
4.1.0
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.0-rc5
1.0.0-rc6
1.0.0-rc7
1.0.0-rc8
1.0.0-rc9
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.10.0
2.10.1
2.10.2
2.11.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.9.0
Fixed in
2.11.1
3.3.6
4.1.1
References
Updated Aug 14, 2026 · Source: OSV.dev | ||
2.4.0
minor
1 CVE
CVE-2026-55590
GHSA-hhpq-7wg4-36jm
Jun 17, 2026
CakePHP Authentication: Open redirect weakness via backslash bypass
Medium
Network
Low
None
ImpactThe Patches2.11.1, 3.3.6 and 4.1.1 contain a fix for this issue. WorkaroundsIf you are unable to upgrade, you should consider adding application validation to the redirect query string parameter to mitigate this vulnerability. Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
+ 59 more Show less
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
4.0.0
4.0.1
4.1.0
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.0-rc5
1.0.0-rc6
1.0.0-rc7
1.0.0-rc8
1.0.0-rc9
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.10.0
2.10.1
2.10.2
2.11.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.9.0
Fixed in
2.11.1
3.3.6
4.1.1
References
Updated Aug 14, 2026 · Source: OSV.dev | ||
2.3.1
patch
1 CVE
CVE-2026-55590
GHSA-hhpq-7wg4-36jm
Jun 17, 2026
CakePHP Authentication: Open redirect weakness via backslash bypass
Medium
Network
Low
None
ImpactThe Patches2.11.1, 3.3.6 and 4.1.1 contain a fix for this issue. WorkaroundsIf you are unable to upgrade, you should consider adding application validation to the redirect query string parameter to mitigate this vulnerability. Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
+ 59 more Show less
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
4.0.0
4.0.1
4.1.0
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.0-rc5
1.0.0-rc6
1.0.0-rc7
1.0.0-rc8
1.0.0-rc9
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.10.0
2.10.1
2.10.2
2.11.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.9.0
Fixed in
2.11.1
3.3.6
4.1.1
References
Updated Aug 14, 2026 · Source: OSV.dev | ||
2.3.0
minor
1 CVE
CVE-2026-55590
GHSA-hhpq-7wg4-36jm
Jun 17, 2026
CakePHP Authentication: Open redirect weakness via backslash bypass
Medium
Network
Low
None
ImpactThe Patches2.11.1, 3.3.6 and 4.1.1 contain a fix for this issue. WorkaroundsIf you are unable to upgrade, you should consider adding application validation to the redirect query string parameter to mitigate this vulnerability. Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
+ 59 more Show less
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
4.0.0
4.0.1
4.1.0
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.0-rc5
1.0.0-rc6
1.0.0-rc7
1.0.0-rc8
1.0.0-rc9
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.10.0
2.10.1
2.10.2
2.11.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.9.0
Fixed in
2.11.1
3.3.6
4.1.1
References
Updated Aug 14, 2026 · Source: OSV.dev | ||
2.2.0
minor
1 CVE
CVE-2026-55590
GHSA-hhpq-7wg4-36jm
Jun 17, 2026
CakePHP Authentication: Open redirect weakness via backslash bypass
Medium
Network
Low
None
ImpactThe Patches2.11.1, 3.3.6 and 4.1.1 contain a fix for this issue. WorkaroundsIf you are unable to upgrade, you should consider adding application validation to the redirect query string parameter to mitigate this vulnerability. Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
+ 59 more Show less
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
4.0.0
4.0.1
4.1.0
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.0-rc5
1.0.0-rc6
1.0.0-rc7
1.0.0-rc8
1.0.0-rc9
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.10.0
2.10.1
2.10.2
2.11.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.9.0
Fixed in
2.11.1
3.3.6
4.1.1
References
Updated Aug 14, 2026 · Source: OSV.dev | ||
2.1.0
minor
1 CVE
CVE-2026-55590
GHSA-hhpq-7wg4-36jm
Jun 17, 2026
CakePHP Authentication: Open redirect weakness via backslash bypass
Medium
Network
Low
None
ImpactThe Patches2.11.1, 3.3.6 and 4.1.1 contain a fix for this issue. WorkaroundsIf you are unable to upgrade, you should consider adding application validation to the redirect query string parameter to mitigate this vulnerability. Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
+ 59 more Show less
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
4.0.0
4.0.1
4.1.0
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.0-rc5
1.0.0-rc6
1.0.0-rc7
1.0.0-rc8
1.0.0-rc9
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.10.0
2.10.1
2.10.2
2.11.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.9.0
Fixed in
2.11.1
3.3.6
4.1.1
References
Updated Aug 14, 2026 · Source: OSV.dev | ||
2.0.5
patch
1 CVE
CVE-2026-55590
GHSA-hhpq-7wg4-36jm
Jun 17, 2026
CakePHP Authentication: Open redirect weakness via backslash bypass
Medium
Network
Low
None
ImpactThe Patches2.11.1, 3.3.6 and 4.1.1 contain a fix for this issue. WorkaroundsIf you are unable to upgrade, you should consider adding application validation to the redirect query string parameter to mitigate this vulnerability. Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
+ 59 more Show less
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
4.0.0
4.0.1
4.1.0
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.0-rc5
1.0.0-rc6
1.0.0-rc7
1.0.0-rc8
1.0.0-rc9
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.10.0
2.10.1
2.10.2
2.11.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.9.0
Fixed in
2.11.1
3.3.6
4.1.1
References
Updated Aug 14, 2026 · Source: OSV.dev | ||
1.4.2
patch
1 CVE
CVE-2026-55590
GHSA-hhpq-7wg4-36jm
Jun 17, 2026
CakePHP Authentication: Open redirect weakness via backslash bypass
Medium
Network
Low
None
ImpactThe Patches2.11.1, 3.3.6 and 4.1.1 contain a fix for this issue. WorkaroundsIf you are unable to upgrade, you should consider adding application validation to the redirect query string parameter to mitigate this vulnerability. Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
+ 59 more Show less
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
4.0.0
4.0.1
4.1.0
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.0-rc5
1.0.0-rc6
1.0.0-rc7
1.0.0-rc8
1.0.0-rc9
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.10.0
2.10.1
2.10.2
2.11.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.9.0
Fixed in
2.11.1
3.3.6
4.1.1
References
Updated Aug 14, 2026 · Source: OSV.dev | ||
2.0.4
patch
1 CVE
CVE-2026-55590
GHSA-hhpq-7wg4-36jm
Jun 17, 2026
CakePHP Authentication: Open redirect weakness via backslash bypass
Medium
Network
Low
None
ImpactThe Patches2.11.1, 3.3.6 and 4.1.1 contain a fix for this issue. WorkaroundsIf you are unable to upgrade, you should consider adding application validation to the redirect query string parameter to mitigate this vulnerability. Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
+ 59 more Show less
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
4.0.0
4.0.1
4.1.0
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.0-rc5
1.0.0-rc6
1.0.0-rc7
1.0.0-rc8
1.0.0-rc9
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.10.0
2.10.1
2.10.2
2.11.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.9.0
Fixed in
2.11.1
3.3.6
4.1.1
References
Updated Aug 14, 2026 · Source: OSV.dev | ||
2.0.3
patch
1 CVE
CVE-2026-55590
GHSA-hhpq-7wg4-36jm
Jun 17, 2026
CakePHP Authentication: Open redirect weakness via backslash bypass
Medium
Network
Low
None
ImpactThe Patches2.11.1, 3.3.6 and 4.1.1 contain a fix for this issue. WorkaroundsIf you are unable to upgrade, you should consider adding application validation to the redirect query string parameter to mitigate this vulnerability. Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
+ 59 more Show less
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
4.0.0
4.0.1
4.1.0
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.0-rc5
1.0.0-rc6
1.0.0-rc7
1.0.0-rc8
1.0.0-rc9
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.10.0
2.10.1
2.10.2
2.11.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.9.0
Fixed in
2.11.1
3.3.6
4.1.1
References
Updated Aug 14, 2026 · Source: OSV.dev | ||
1.4.1
patch
1 CVE
CVE-2026-55590
GHSA-hhpq-7wg4-36jm
Jun 17, 2026
CakePHP Authentication: Open redirect weakness via backslash bypass
Medium
Network
Low
None
ImpactThe Patches2.11.1, 3.3.6 and 4.1.1 contain a fix for this issue. WorkaroundsIf you are unable to upgrade, you should consider adding application validation to the redirect query string parameter to mitigate this vulnerability. Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
+ 59 more Show less
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
4.0.0
4.0.1
4.1.0
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.0-rc5
1.0.0-rc6
1.0.0-rc7
1.0.0-rc8
1.0.0-rc9
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.10.0
2.10.1
2.10.2
2.11.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.9.0
Fixed in
2.11.1
3.3.6
4.1.1
References
Updated Aug 14, 2026 · Source: OSV.dev | ||
2.0.2
patch
1 CVE
CVE-2026-55590
GHSA-hhpq-7wg4-36jm
Jun 17, 2026
CakePHP Authentication: Open redirect weakness via backslash bypass
Medium
Network
Low
None
ImpactThe Patches2.11.1, 3.3.6 and 4.1.1 contain a fix for this issue. WorkaroundsIf you are unable to upgrade, you should consider adding application validation to the redirect query string parameter to mitigate this vulnerability. Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
+ 59 more Show less
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
4.0.0
4.0.1
4.1.0
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.0-rc5
1.0.0-rc6
1.0.0-rc7
1.0.0-rc8
1.0.0-rc9
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.10.0
2.10.1
2.10.2
2.11.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.9.0
Fixed in
2.11.1
3.3.6
4.1.1
References
Updated Aug 14, 2026 · Source: OSV.dev |