2.11.2
patch
1 CVE
CVE-2026-55590
GHSA-hhpq-7wg4-36jm
Jun 17, 2026
CakePHP Authentication: Open redirect weakness via backslash bypass
Impact
The getLoginRedirect() method contains a weakness to backslash bypasses allowing redirect targets with attacker controlled hostnames.
Patches
3.3.6 and 4.1.1 contain a fix for this issue.
Workarounds
If you are unable to upgrade, you should consider adding application validation to the redirect query string parameter to mitigate this vulnerability.
Affected versions
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.0-rc5
1.0.0-rc6
+ 59 more
Show less
1.0.0-rc7
1.0.0-rc8
1.0.0-rc9
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.10.0
2.10.1
2.10.2
2.11.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
4.0.0
4.0.1
4.1.0
Updated Jun 17, 2026 · Source: OSV.dev
|
|
- Released
- Jul 10, 2026
- Checksum
-
Dependencies
(6)
-
cakephp/http
^4.5
-
laminas/laminas-diactoros
^2.2.2
-
psr/http-client
^1.0
-
psr/http-message
^1.0
-
psr/http-server-handler
^1.0
-
psr/http-server-middleware
^1.0
|
|
3.3.7
patch
|
|
- Released
- Jul 08, 2026
- Runtime
-
>=8.1
- Checksum
-
Dependencies
(6)
-
cakephp/http
^5.0
-
laminas/laminas-diactoros
^3.0
-
psr/http-client
^1.0
-
psr/http-message
^1.1 || ^2.0
-
psr/http-server-handler
^1.0
-
psr/http-server-middleware
^1.0
|
|
4.2.1
patch
|
|
- Released
- Jul 08, 2026
- License
- MIT
- Runtime
-
>=8.1
- Checksum
-
- Funding
-
[]
Dependencies
(7)
-
cakephp/http
^5.0
-
cakephp/utility
^5.0
-
laminas/laminas-diactoros
^3.0
-
psr/http-client
^1.0
-
psr/http-message
^1.1 || ^2.0
-
psr/http-server-handler
^1.0
-
psr/http-server-middleware
^1.0
|
2.11.1
patch
1 CVE
CVE-2026-55590
GHSA-hhpq-7wg4-36jm
Jun 17, 2026
CakePHP Authentication: Open redirect weakness via backslash bypass
Impact
The getLoginRedirect() method contains a weakness to backslash bypasses allowing redirect targets with attacker controlled hostnames.
Patches
3.3.6 and 4.1.1 contain a fix for this issue.
Workarounds
If you are unable to upgrade, you should consider adding application validation to the redirect query string parameter to mitigate this vulnerability.
Affected versions
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.0-rc5
1.0.0-rc6
+ 59 more
Show less
1.0.0-rc7
1.0.0-rc8
1.0.0-rc9
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.10.0
2.10.1
2.10.2
2.11.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
4.0.0
4.0.1
4.1.0
Updated Jun 17, 2026 · Source: OSV.dev
|
|
- Released
- Jun 25, 2026
- Checksum
-
|
|
4.2.0
minor
|
|
- Released
- Jun 21, 2026
- Checksum
-
|
|
3.3.6
patch
|
|
- Released
- Jun 14, 2026
- Checksum
-
|
|
4.1.1
patch
|
|
- Released
- Jun 13, 2026
- Checksum
-
|
4.1.0
minor
1 CVE
CVE-2026-55590
GHSA-hhpq-7wg4-36jm
Jun 17, 2026
CakePHP Authentication: Open redirect weakness via backslash bypass
Impact
The getLoginRedirect() method contains a weakness to backslash bypasses allowing redirect targets with attacker controlled hostnames.
Patches
3.3.6 and 4.1.1 contain a fix for this issue.
Workarounds
If you are unable to upgrade, you should consider adding application validation to the redirect query string parameter to mitigate this vulnerability.
Affected versions
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.0-rc5
1.0.0-rc6
+ 59 more
Show less
1.0.0-rc7
1.0.0-rc8
1.0.0-rc9
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.10.0
2.10.1
2.10.2
2.11.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
4.0.0
4.0.1
4.1.0
Updated Jun 17, 2026 · Source: OSV.dev
|
|
- Released
- Apr 22, 2026
- Checksum
-
|
4.0.1
patch
1 CVE
CVE-2026-55590
GHSA-hhpq-7wg4-36jm
Jun 17, 2026
CakePHP Authentication: Open redirect weakness via backslash bypass
Impact
The getLoginRedirect() method contains a weakness to backslash bypasses allowing redirect targets with attacker controlled hostnames.
Patches
3.3.6 and 4.1.1 contain a fix for this issue.
Workarounds
If you are unable to upgrade, you should consider adding application validation to the redirect query string parameter to mitigate this vulnerability.
Affected versions
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.0-rc5
1.0.0-rc6
+ 59 more
Show less
1.0.0-rc7
1.0.0-rc8
1.0.0-rc9
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.10.0
2.10.1
2.10.2
2.11.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
4.0.0
4.0.1
4.1.0
Updated Jun 17, 2026 · Source: OSV.dev
|
|
- Released
- Feb 27, 2026
- Checksum
-
|
4.0.0
major
1 CVE
CVE-2026-55590
GHSA-hhpq-7wg4-36jm
Jun 17, 2026
CakePHP Authentication: Open redirect weakness via backslash bypass
Impact
The getLoginRedirect() method contains a weakness to backslash bypasses allowing redirect targets with attacker controlled hostnames.
Patches
3.3.6 and 4.1.1 contain a fix for this issue.
Workarounds
If you are unable to upgrade, you should consider adding application validation to the redirect query string parameter to mitigate this vulnerability.
Affected versions
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.0-rc5
1.0.0-rc6
+ 59 more
Show less
1.0.0-rc7
1.0.0-rc8
1.0.0-rc9
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.10.0
2.10.1
2.10.2
2.11.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
4.0.0
4.0.1
4.1.0
Updated Jun 17, 2026 · Source: OSV.dev
|
|
- Released
- Feb 01, 2026
- Checksum
-
|
3.3.5
patch
1 CVE
CVE-2026-55590
GHSA-hhpq-7wg4-36jm
Jun 17, 2026
CakePHP Authentication: Open redirect weakness via backslash bypass
Impact
The getLoginRedirect() method contains a weakness to backslash bypasses allowing redirect targets with attacker controlled hostnames.
Patches
3.3.6 and 4.1.1 contain a fix for this issue.
Workarounds
If you are unable to upgrade, you should consider adding application validation to the redirect query string parameter to mitigate this vulnerability.
Affected versions
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.0-rc5
1.0.0-rc6
+ 59 more
Show less
1.0.0-rc7
1.0.0-rc8
1.0.0-rc9
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.10.0
2.10.1
2.10.2
2.11.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
4.0.0
4.0.1
4.1.0
Updated Jun 17, 2026 · Source: OSV.dev
|
|
- Released
- Jan 31, 2026
- Checksum
-
|
3.3.4
patch
1 CVE
CVE-2026-55590
GHSA-hhpq-7wg4-36jm
Jun 17, 2026
CakePHP Authentication: Open redirect weakness via backslash bypass
Impact
The getLoginRedirect() method contains a weakness to backslash bypasses allowing redirect targets with attacker controlled hostnames.
Patches
3.3.6 and 4.1.1 contain a fix for this issue.
Workarounds
If you are unable to upgrade, you should consider adding application validation to the redirect query string parameter to mitigate this vulnerability.
Affected versions
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.0-rc5
1.0.0-rc6
+ 59 more
Show less
1.0.0-rc7
1.0.0-rc8
1.0.0-rc9
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.10.0
2.10.1
2.10.2
2.11.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
4.0.0
4.0.1
4.1.0
Updated Jun 17, 2026 · Source: OSV.dev
|
|
- Released
- Nov 29, 2025
- Checksum
-
|
3.3.3
patch
1 CVE
CVE-2026-55590
GHSA-hhpq-7wg4-36jm
Jun 17, 2026
CakePHP Authentication: Open redirect weakness via backslash bypass
Impact
The getLoginRedirect() method contains a weakness to backslash bypasses allowing redirect targets with attacker controlled hostnames.
Patches
3.3.6 and 4.1.1 contain a fix for this issue.
Workarounds
If you are unable to upgrade, you should consider adding application validation to the redirect query string parameter to mitigate this vulnerability.
Affected versions
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.0-rc5
1.0.0-rc6
+ 59 more
Show less
1.0.0-rc7
1.0.0-rc8
1.0.0-rc9
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.10.0
2.10.1
2.10.2
2.11.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
4.0.0
4.0.1
4.1.0
Updated Jun 17, 2026 · Source: OSV.dev
|
|
- Released
- Nov 06, 2025
- Checksum
-
|
3.3.2
patch
1 CVE
CVE-2026-55590
GHSA-hhpq-7wg4-36jm
Jun 17, 2026
CakePHP Authentication: Open redirect weakness via backslash bypass
Impact
The getLoginRedirect() method contains a weakness to backslash bypasses allowing redirect targets with attacker controlled hostnames.
Patches
3.3.6 and 4.1.1 contain a fix for this issue.
Workarounds
If you are unable to upgrade, you should consider adding application validation to the redirect query string parameter to mitigate this vulnerability.
Affected versions
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.0-rc5
1.0.0-rc6
+ 59 more
Show less
1.0.0-rc7
1.0.0-rc8
1.0.0-rc9
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.10.0
2.10.1
2.10.2
2.11.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
4.0.0
4.0.1
4.1.0
Updated Jun 17, 2026 · Source: OSV.dev
|
|
- Released
- Jul 30, 2025
- Checksum
-
|
3.3.1
patch
1 CVE
CVE-2026-55590
GHSA-hhpq-7wg4-36jm
Jun 17, 2026
CakePHP Authentication: Open redirect weakness via backslash bypass
Impact
The getLoginRedirect() method contains a weakness to backslash bypasses allowing redirect targets with attacker controlled hostnames.
Patches
3.3.6 and 4.1.1 contain a fix for this issue.
Workarounds
If you are unable to upgrade, you should consider adding application validation to the redirect query string parameter to mitigate this vulnerability.
Affected versions
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.0-rc5
1.0.0-rc6
+ 59 more
Show less
1.0.0-rc7
1.0.0-rc8
1.0.0-rc9
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.10.0
2.10.1
2.10.2
2.11.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
4.0.0
4.0.1
4.1.0
Updated Jun 17, 2026 · Source: OSV.dev
|
|
- Released
- Jul 27, 2025
- Checksum
-
|
3.3.0
minor
1 CVE
CVE-2026-55590
GHSA-hhpq-7wg4-36jm
Jun 17, 2026
CakePHP Authentication: Open redirect weakness via backslash bypass
Impact
The getLoginRedirect() method contains a weakness to backslash bypasses allowing redirect targets with attacker controlled hostnames.
Patches
3.3.6 and 4.1.1 contain a fix for this issue.
Workarounds
If you are unable to upgrade, you should consider adding application validation to the redirect query string parameter to mitigate this vulnerability.
Affected versions
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.0-rc5
1.0.0-rc6
+ 59 more
Show less
1.0.0-rc7
1.0.0-rc8
1.0.0-rc9
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.10.0
2.10.1
2.10.2
2.11.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
4.0.0
4.0.1
4.1.0
Updated Jun 17, 2026 · Source: OSV.dev
|
|
- Released
- Jul 13, 2025
- Checksum
-
|
3.2.5
patch
1 CVE
CVE-2026-55590
GHSA-hhpq-7wg4-36jm
Jun 17, 2026
CakePHP Authentication: Open redirect weakness via backslash bypass
Impact
The getLoginRedirect() method contains a weakness to backslash bypasses allowing redirect targets with attacker controlled hostnames.
Patches
3.3.6 and 4.1.1 contain a fix for this issue.
Workarounds
If you are unable to upgrade, you should consider adding application validation to the redirect query string parameter to mitigate this vulnerability.
Affected versions
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.0-rc5
1.0.0-rc6
+ 59 more
Show less
1.0.0-rc7
1.0.0-rc8
1.0.0-rc9
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.10.0
2.10.1
2.10.2
2.11.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
4.0.0
4.0.1
4.1.0
Updated Jun 17, 2026 · Source: OSV.dev
|
|
- Released
- May 14, 2025
- Checksum
-
|
3.2.4
patch
1 CVE
CVE-2026-55590
GHSA-hhpq-7wg4-36jm
Jun 17, 2026
CakePHP Authentication: Open redirect weakness via backslash bypass
Impact
The getLoginRedirect() method contains a weakness to backslash bypasses allowing redirect targets with attacker controlled hostnames.
Patches
3.3.6 and 4.1.1 contain a fix for this issue.
Workarounds
If you are unable to upgrade, you should consider adding application validation to the redirect query string parameter to mitigate this vulnerability.
Affected versions
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.0-rc5
1.0.0-rc6
+ 59 more
Show less
1.0.0-rc7
1.0.0-rc8
1.0.0-rc9
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.10.0
2.10.1
2.10.2
2.11.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
4.0.0
4.0.1
4.1.0
Updated Jun 17, 2026 · Source: OSV.dev
|
|
- Released
- Apr 28, 2025
- Checksum
-
|
3.2.3
patch
1 CVE
CVE-2026-55590
GHSA-hhpq-7wg4-36jm
Jun 17, 2026
CakePHP Authentication: Open redirect weakness via backslash bypass
Impact
The getLoginRedirect() method contains a weakness to backslash bypasses allowing redirect targets with attacker controlled hostnames.
Patches
3.3.6 and 4.1.1 contain a fix for this issue.
Workarounds
If you are unable to upgrade, you should consider adding application validation to the redirect query string parameter to mitigate this vulnerability.
Affected versions
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.0-rc5
1.0.0-rc6
+ 59 more
Show less
1.0.0-rc7
1.0.0-rc8
1.0.0-rc9
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.10.0
2.10.1
2.10.2
2.11.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
4.0.0
4.0.1
4.1.0
Updated Jun 17, 2026 · Source: OSV.dev
|
|
- Released
- Apr 20, 2025
- Checksum
-
|
3.2.2
patch
1 CVE
CVE-2026-55590
GHSA-hhpq-7wg4-36jm
Jun 17, 2026
CakePHP Authentication: Open redirect weakness via backslash bypass
Impact
The getLoginRedirect() method contains a weakness to backslash bypasses allowing redirect targets with attacker controlled hostnames.
Patches
3.3.6 and 4.1.1 contain a fix for this issue.
Workarounds
If you are unable to upgrade, you should consider adding application validation to the redirect query string parameter to mitigate this vulnerability.
Affected versions
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.0-rc5
1.0.0-rc6
+ 59 more
Show less
1.0.0-rc7
1.0.0-rc8
1.0.0-rc9
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.10.0
2.10.1
2.10.2
2.11.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
4.0.0
4.0.1
4.1.0
Updated Jun 17, 2026 · Source: OSV.dev
|
|
- Released
- Mar 20, 2025
- Checksum
-
Dependencies
(6)
-
cakephp/http
^5.0
-
laminas/laminas-diactoros
^3.0
-
psr/http-client
^1.0
-
psr/http-message
^1.1 || ^2.0
-
psr/http-server-handler
^1.0
-
psr/http-server-middleware
^1.0
|
3.2.1
patch
1 CVE
CVE-2026-55590
GHSA-hhpq-7wg4-36jm
Jun 17, 2026
CakePHP Authentication: Open redirect weakness via backslash bypass
Impact
The getLoginRedirect() method contains a weakness to backslash bypasses allowing redirect targets with attacker controlled hostnames.
Patches
3.3.6 and 4.1.1 contain a fix for this issue.
Workarounds
If you are unable to upgrade, you should consider adding application validation to the redirect query string parameter to mitigate this vulnerability.
Affected versions
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.0-rc5
1.0.0-rc6
+ 59 more
Show less
1.0.0-rc7
1.0.0-rc8
1.0.0-rc9
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.10.0
2.10.1
2.10.2
2.11.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
4.0.0
4.0.1
4.1.0
Updated Jun 17, 2026 · Source: OSV.dev
|
|
- Released
- Oct 18, 2024
- Checksum
-
|
2.11.0
minor
1 CVE
CVE-2026-55590
GHSA-hhpq-7wg4-36jm
Jun 17, 2026
CakePHP Authentication: Open redirect weakness via backslash bypass
Impact
The getLoginRedirect() method contains a weakness to backslash bypasses allowing redirect targets with attacker controlled hostnames.
Patches
3.3.6 and 4.1.1 contain a fix for this issue.
Workarounds
If you are unable to upgrade, you should consider adding application validation to the redirect query string parameter to mitigate this vulnerability.
Affected versions
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.0-rc5
1.0.0-rc6
+ 59 more
Show less
1.0.0-rc7
1.0.0-rc8
1.0.0-rc9
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.10.0
2.10.1
2.10.2
2.11.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
4.0.0
4.0.1
4.1.0
Updated Jun 17, 2026 · Source: OSV.dev
|
|
- Released
- Oct 18, 2024
- Checksum
-
|
3.2.0
minor
1 CVE
CVE-2026-55590
GHSA-hhpq-7wg4-36jm
Jun 17, 2026
CakePHP Authentication: Open redirect weakness via backslash bypass
Impact
The getLoginRedirect() method contains a weakness to backslash bypasses allowing redirect targets with attacker controlled hostnames.
Patches
3.3.6 and 4.1.1 contain a fix for this issue.
Workarounds
If you are unable to upgrade, you should consider adding application validation to the redirect query string parameter to mitigate this vulnerability.
Affected versions
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.0-rc5
1.0.0-rc6
+ 59 more
Show less
1.0.0-rc7
1.0.0-rc8
1.0.0-rc9
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.10.0
2.10.1
2.10.2
2.11.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
4.0.0
4.0.1
4.1.0
Updated Jun 17, 2026 · Source: OSV.dev
|
|
- Released
- Oct 18, 2024
- Checksum
-
|
3.1.1
patch
1 CVE
CVE-2026-55590
GHSA-hhpq-7wg4-36jm
Jun 17, 2026
CakePHP Authentication: Open redirect weakness via backslash bypass
Impact
The getLoginRedirect() method contains a weakness to backslash bypasses allowing redirect targets with attacker controlled hostnames.
Patches
3.3.6 and 4.1.1 contain a fix for this issue.
Workarounds
If you are unable to upgrade, you should consider adding application validation to the redirect query string parameter to mitigate this vulnerability.
Affected versions
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.0-rc5
1.0.0-rc6
+ 59 more
Show less
1.0.0-rc7
1.0.0-rc8
1.0.0-rc9
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.10.0
2.10.1
2.10.2
2.11.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
4.0.0
4.0.1
4.1.0
Updated Jun 17, 2026 · Source: OSV.dev
|
|
- Released
- Oct 07, 2024
- Checksum
-
|
3.1.0
minor
1 CVE
CVE-2026-55590
GHSA-hhpq-7wg4-36jm
Jun 17, 2026
CakePHP Authentication: Open redirect weakness via backslash bypass
Impact
The getLoginRedirect() method contains a weakness to backslash bypasses allowing redirect targets with attacker controlled hostnames.
Patches
3.3.6 and 4.1.1 contain a fix for this issue.
Workarounds
If you are unable to upgrade, you should consider adding application validation to the redirect query string parameter to mitigate this vulnerability.
Affected versions
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.0-rc5
1.0.0-rc6
+ 59 more
Show less
1.0.0-rc7
1.0.0-rc8
1.0.0-rc9
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.10.0
2.10.1
2.10.2
2.11.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
4.0.0
4.0.1
4.1.0
Updated Jun 17, 2026 · Source: OSV.dev
|
|
- Released
- Jul 28, 2024
- Checksum
-
|
3.0.3
patch
1 CVE
CVE-2026-55590
GHSA-hhpq-7wg4-36jm
Jun 17, 2026
CakePHP Authentication: Open redirect weakness via backslash bypass
Impact
The getLoginRedirect() method contains a weakness to backslash bypasses allowing redirect targets with attacker controlled hostnames.
Patches
3.3.6 and 4.1.1 contain a fix for this issue.
Workarounds
If you are unable to upgrade, you should consider adding application validation to the redirect query string parameter to mitigate this vulnerability.
Affected versions
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.0-rc5
1.0.0-rc6
+ 59 more
Show less
1.0.0-rc7
1.0.0-rc8
1.0.0-rc9
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.10.0
2.10.1
2.10.2
2.11.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
4.0.0
4.0.1
4.1.0
Updated Jun 17, 2026 · Source: OSV.dev
|
|
- Released
- Dec 01, 2023
- Checksum
-
|
2.10.2
patch
1 CVE
CVE-2026-55590
GHSA-hhpq-7wg4-36jm
Jun 17, 2026
CakePHP Authentication: Open redirect weakness via backslash bypass
Impact
The getLoginRedirect() method contains a weakness to backslash bypasses allowing redirect targets with attacker controlled hostnames.
Patches
3.3.6 and 4.1.1 contain a fix for this issue.
Workarounds
If you are unable to upgrade, you should consider adding application validation to the redirect query string parameter to mitigate this vulnerability.
Affected versions
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.0-rc5
1.0.0-rc6
+ 59 more
Show less
1.0.0-rc7
1.0.0-rc8
1.0.0-rc9
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.10.0
2.10.1
2.10.2
2.11.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
4.0.0
4.0.1
4.1.0
Updated Jun 17, 2026 · Source: OSV.dev
|
|
- Released
- Oct 01, 2023
- Checksum
-
Dependencies
(6)
-
cakephp/http
^4.4
-
laminas/laminas-diactoros
^2.2.2
-
psr/http-client
^1.0
-
psr/http-message
^1.0
-
psr/http-server-handler
^1.0
-
psr/http-server-middleware
^1.0
|
3.0.2
patch
1 CVE
CVE-2026-55590
GHSA-hhpq-7wg4-36jm
Jun 17, 2026
CakePHP Authentication: Open redirect weakness via backslash bypass
Impact
The getLoginRedirect() method contains a weakness to backslash bypasses allowing redirect targets with attacker controlled hostnames.
Patches
3.3.6 and 4.1.1 contain a fix for this issue.
Workarounds
If you are unable to upgrade, you should consider adding application validation to the redirect query string parameter to mitigate this vulnerability.
Affected versions
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.0-rc5
1.0.0-rc6
+ 59 more
Show less
1.0.0-rc7
1.0.0-rc8
1.0.0-rc9
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.10.0
2.10.1
2.10.2
2.11.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
4.0.0
4.0.1
4.1.0
Updated Jun 17, 2026 · Source: OSV.dev
|
|
- Released
- Sep 10, 2023
- Checksum
-
Dependencies
(6)
-
cakephp/http
^5.0
-
laminas/laminas-diactoros
^3.0
-
psr/http-client
^1.0
-
psr/http-message
^2.0
-
psr/http-server-handler
^1.0
-
psr/http-server-middleware
^1.0
|
3.0.1
major
1 CVE
CVE-2026-55590
GHSA-hhpq-7wg4-36jm
Jun 17, 2026
CakePHP Authentication: Open redirect weakness via backslash bypass
Impact
The getLoginRedirect() method contains a weakness to backslash bypasses allowing redirect targets with attacker controlled hostnames.
Patches
3.3.6 and 4.1.1 contain a fix for this issue.
Workarounds
If you are unable to upgrade, you should consider adding application validation to the redirect query string parameter to mitigate this vulnerability.
Affected versions
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.0-rc5
1.0.0-rc6
+ 59 more
Show less
1.0.0-rc7
1.0.0-rc8
1.0.0-rc9
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.10.0
2.10.1
2.10.2
2.11.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
4.0.0
4.0.1
4.1.0
Updated Jun 17, 2026 · Source: OSV.dev
|
|
- Released
- Sep 05, 2023
- Checksum
-
Dependencies
(6)
-
cakephp/http
5.x-dev
-
laminas/laminas-diactoros
^3.0
-
psr/http-client
^1.0
-
psr/http-message
^2.0
-
psr/http-server-handler
^1.0
-
psr/http-server-middleware
^1.0
|
2.10.1
patch
1 CVE
CVE-2026-55590
GHSA-hhpq-7wg4-36jm
Jun 17, 2026
CakePHP Authentication: Open redirect weakness via backslash bypass
Impact
The getLoginRedirect() method contains a weakness to backslash bypasses allowing redirect targets with attacker controlled hostnames.
Patches
3.3.6 and 4.1.1 contain a fix for this issue.
Workarounds
If you are unable to upgrade, you should consider adding application validation to the redirect query string parameter to mitigate this vulnerability.
Affected versions
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.0-rc5
1.0.0-rc6
+ 59 more
Show less
1.0.0-rc7
1.0.0-rc8
1.0.0-rc9
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.10.0
2.10.1
2.10.2
2.11.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
4.0.0
4.0.1
4.1.0
Updated Jun 17, 2026 · Source: OSV.dev
|
|
- Released
- Mar 17, 2023
- Checksum
-
|
2.10.0
minor
1 CVE
CVE-2026-55590
GHSA-hhpq-7wg4-36jm
Jun 17, 2026
CakePHP Authentication: Open redirect weakness via backslash bypass
Impact
The getLoginRedirect() method contains a weakness to backslash bypasses allowing redirect targets with attacker controlled hostnames.
Patches
3.3.6 and 4.1.1 contain a fix for this issue.
Workarounds
If you are unable to upgrade, you should consider adding application validation to the redirect query string parameter to mitigate this vulnerability.
Affected versions
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.0-rc5
1.0.0-rc6
+ 59 more
Show less
1.0.0-rc7
1.0.0-rc8
1.0.0-rc9
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.10.0
2.10.1
2.10.2
2.11.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
4.0.0
4.0.1
4.1.0
Updated Jun 17, 2026 · Source: OSV.dev
|
|
- Released
- Dec 04, 2022
- Checksum
-
|
2.9.0
minor
1 CVE
CVE-2026-55590
GHSA-hhpq-7wg4-36jm
Jun 17, 2026
CakePHP Authentication: Open redirect weakness via backslash bypass
Impact
The getLoginRedirect() method contains a weakness to backslash bypasses allowing redirect targets with attacker controlled hostnames.
Patches
3.3.6 and 4.1.1 contain a fix for this issue.
Workarounds
If you are unable to upgrade, you should consider adding application validation to the redirect query string parameter to mitigate this vulnerability.
Affected versions
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.0-rc5
1.0.0-rc6
+ 59 more
Show less
1.0.0-rc7
1.0.0-rc8
1.0.0-rc9
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.10.0
2.10.1
2.10.2
2.11.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
4.0.0
4.0.1
4.1.0
Updated Jun 17, 2026 · Source: OSV.dev
|
|
- Released
- Jan 06, 2022
- Checksum
-
Dependencies
(6)
-
cakephp/http
^4.0
-
laminas/laminas-diactoros
^2.2.2
-
psr/http-client
^1.0
-
psr/http-message
^1.0
-
psr/http-server-handler
^1.0
-
psr/http-server-middleware
^1.0
|
2.8.0
minor
1 CVE
CVE-2026-55590
GHSA-hhpq-7wg4-36jm
Jun 17, 2026
CakePHP Authentication: Open redirect weakness via backslash bypass
Impact
The getLoginRedirect() method contains a weakness to backslash bypasses allowing redirect targets with attacker controlled hostnames.
Patches
3.3.6 and 4.1.1 contain a fix for this issue.
Workarounds
If you are unable to upgrade, you should consider adding application validation to the redirect query string parameter to mitigate this vulnerability.
Affected versions
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.0-rc5
1.0.0-rc6
+ 59 more
Show less
1.0.0-rc7
1.0.0-rc8
1.0.0-rc9
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.10.0
2.10.1
2.10.2
2.11.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
4.0.0
4.0.1
4.1.0
Updated Jun 17, 2026 · Source: OSV.dev
|
|
- Released
- Jan 04, 2022
- Checksum
-
|
2.7.0
minor
1 CVE
CVE-2026-55590
GHSA-hhpq-7wg4-36jm
Jun 17, 2026
CakePHP Authentication: Open redirect weakness via backslash bypass
Impact
The getLoginRedirect() method contains a weakness to backslash bypasses allowing redirect targets with attacker controlled hostnames.
Patches
3.3.6 and 4.1.1 contain a fix for this issue.
Workarounds
If you are unable to upgrade, you should consider adding application validation to the redirect query string parameter to mitigate this vulnerability.
Affected versions
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.0-rc5
1.0.0-rc6
+ 59 more
Show less
1.0.0-rc7
1.0.0-rc8
1.0.0-rc9
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.10.0
2.10.1
2.10.2
2.11.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
4.0.0
4.0.1
4.1.0
Updated Jun 17, 2026 · Source: OSV.dev
|
|
- Released
- Nov 25, 2021
- Checksum
-
|
2.6.2
patch
1 CVE
CVE-2026-55590
GHSA-hhpq-7wg4-36jm
Jun 17, 2026
CakePHP Authentication: Open redirect weakness via backslash bypass
Impact
The getLoginRedirect() method contains a weakness to backslash bypasses allowing redirect targets with attacker controlled hostnames.
Patches
3.3.6 and 4.1.1 contain a fix for this issue.
Workarounds
If you are unable to upgrade, you should consider adding application validation to the redirect query string parameter to mitigate this vulnerability.
Affected versions
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.0-rc5
1.0.0-rc6
+ 59 more
Show less
1.0.0-rc7
1.0.0-rc8
1.0.0-rc9
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.10.0
2.10.1
2.10.2
2.11.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
4.0.0
4.0.1
4.1.0
Updated Jun 17, 2026 · Source: OSV.dev
|
|
- Released
- Nov 25, 2021
- Checksum
-
|
2.6.1
patch
1 CVE
CVE-2026-55590
GHSA-hhpq-7wg4-36jm
Jun 17, 2026
CakePHP Authentication: Open redirect weakness via backslash bypass
Impact
The getLoginRedirect() method contains a weakness to backslash bypasses allowing redirect targets with attacker controlled hostnames.
Patches
3.3.6 and 4.1.1 contain a fix for this issue.
Workarounds
If you are unable to upgrade, you should consider adding application validation to the redirect query string parameter to mitigate this vulnerability.
Affected versions
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.0-rc5
1.0.0-rc6
+ 59 more
Show less
1.0.0-rc7
1.0.0-rc8
1.0.0-rc9
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.10.0
2.10.1
2.10.2
2.11.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
4.0.0
4.0.1
4.1.0
Updated Jun 17, 2026 · Source: OSV.dev
|
|
- Released
- Apr 23, 2021
- Checksum
-
|
2.6.0
minor
1 CVE
CVE-2026-55590
GHSA-hhpq-7wg4-36jm
Jun 17, 2026
CakePHP Authentication: Open redirect weakness via backslash bypass
Impact
The getLoginRedirect() method contains a weakness to backslash bypasses allowing redirect targets with attacker controlled hostnames.
Patches
3.3.6 and 4.1.1 contain a fix for this issue.
Workarounds
If you are unable to upgrade, you should consider adding application validation to the redirect query string parameter to mitigate this vulnerability.
Affected versions
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.0-rc5
1.0.0-rc6
+ 59 more
Show less
1.0.0-rc7
1.0.0-rc8
1.0.0-rc9
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.10.0
2.10.1
2.10.2
2.11.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
4.0.0
4.0.1
4.1.0
Updated Jun 17, 2026 · Source: OSV.dev
|
|
- Released
- Feb 11, 2021
- Checksum
-
|
2.5.0
minor
1 CVE
CVE-2026-55590
GHSA-hhpq-7wg4-36jm
Jun 17, 2026
CakePHP Authentication: Open redirect weakness via backslash bypass
Impact
The getLoginRedirect() method contains a weakness to backslash bypasses allowing redirect targets with attacker controlled hostnames.
Patches
3.3.6 and 4.1.1 contain a fix for this issue.
Workarounds
If you are unable to upgrade, you should consider adding application validation to the redirect query string parameter to mitigate this vulnerability.
Affected versions
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.0-rc5
1.0.0-rc6
+ 59 more
Show less
1.0.0-rc7
1.0.0-rc8
1.0.0-rc9
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.10.0
2.10.1
2.10.2
2.11.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
4.0.0
4.0.1
4.1.0
Updated Jun 17, 2026 · Source: OSV.dev
|
|
- Released
- Jan 05, 2021
- Checksum
-
|
2.4.0
minor
1 CVE
CVE-2026-55590
GHSA-hhpq-7wg4-36jm
Jun 17, 2026
CakePHP Authentication: Open redirect weakness via backslash bypass
Impact
The getLoginRedirect() method contains a weakness to backslash bypasses allowing redirect targets with attacker controlled hostnames.
Patches
3.3.6 and 4.1.1 contain a fix for this issue.
Workarounds
If you are unable to upgrade, you should consider adding application validation to the redirect query string parameter to mitigate this vulnerability.
Affected versions
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.0-rc5
1.0.0-rc6
+ 59 more
Show less
1.0.0-rc7
1.0.0-rc8
1.0.0-rc9
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.10.0
2.10.1
2.10.2
2.11.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
4.0.0
4.0.1
4.1.0
Updated Jun 17, 2026 · Source: OSV.dev
|
|
- Released
- Dec 29, 2020
- Checksum
-
Dependencies
(6)
-
cakephp/core
^4.0
-
laminas/laminas-diactoros
^2.2.2
-
psr/http-client
^1.0
-
psr/http-message
^1.0
-
psr/http-server-handler
^1.0
-
psr/http-server-middleware
^1.0
|
2.3.1
patch
1 CVE
CVE-2026-55590
GHSA-hhpq-7wg4-36jm
Jun 17, 2026
CakePHP Authentication: Open redirect weakness via backslash bypass
Impact
The getLoginRedirect() method contains a weakness to backslash bypasses allowing redirect targets with attacker controlled hostnames.
Patches
3.3.6 and 4.1.1 contain a fix for this issue.
Workarounds
If you are unable to upgrade, you should consider adding application validation to the redirect query string parameter to mitigate this vulnerability.
Affected versions
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.0-rc5
1.0.0-rc6
+ 59 more
Show less
1.0.0-rc7
1.0.0-rc8
1.0.0-rc9
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.10.0
2.10.1
2.10.2
2.11.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
4.0.0
4.0.1
4.1.0
Updated Jun 17, 2026 · Source: OSV.dev
|
|
- Released
- Nov 14, 2020
- Checksum
-
Dependencies
(6)
-
cakephp/core
^4.0
-
psr/http-client
^1.0
-
psr/http-message
^1.0
-
psr/http-server-handler
^1.0
-
psr/http-server-middleware
^1.0
-
zendframework/zend-diactoros
^2.0
|
2.3.0
minor
1 CVE
CVE-2026-55590
GHSA-hhpq-7wg4-36jm
Jun 17, 2026
CakePHP Authentication: Open redirect weakness via backslash bypass
Impact
The getLoginRedirect() method contains a weakness to backslash bypasses allowing redirect targets with attacker controlled hostnames.
Patches
3.3.6 and 4.1.1 contain a fix for this issue.
Workarounds
If you are unable to upgrade, you should consider adding application validation to the redirect query string parameter to mitigate this vulnerability.
Affected versions
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.0-rc5
1.0.0-rc6
+ 59 more
Show less
1.0.0-rc7
1.0.0-rc8
1.0.0-rc9
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.10.0
2.10.1
2.10.2
2.11.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
4.0.0
4.0.1
4.1.0
Updated Jun 17, 2026 · Source: OSV.dev
|
|
- Released
- May 17, 2020
- Checksum
-
|
2.2.0
minor
1 CVE
CVE-2026-55590
GHSA-hhpq-7wg4-36jm
Jun 17, 2026
CakePHP Authentication: Open redirect weakness via backslash bypass
Impact
The getLoginRedirect() method contains a weakness to backslash bypasses allowing redirect targets with attacker controlled hostnames.
Patches
3.3.6 and 4.1.1 contain a fix for this issue.
Workarounds
If you are unable to upgrade, you should consider adding application validation to the redirect query string parameter to mitigate this vulnerability.
Affected versions
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.0-rc5
1.0.0-rc6
+ 59 more
Show less
1.0.0-rc7
1.0.0-rc8
1.0.0-rc9
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.10.0
2.10.1
2.10.2
2.11.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
4.0.0
4.0.1
4.1.0
Updated Jun 17, 2026 · Source: OSV.dev
|
|
- Released
- May 09, 2020
- Checksum
-
|
2.1.0
minor
1 CVE
CVE-2026-55590
GHSA-hhpq-7wg4-36jm
Jun 17, 2026
CakePHP Authentication: Open redirect weakness via backslash bypass
Impact
The getLoginRedirect() method contains a weakness to backslash bypasses allowing redirect targets with attacker controlled hostnames.
Patches
3.3.6 and 4.1.1 contain a fix for this issue.
Workarounds
If you are unable to upgrade, you should consider adding application validation to the redirect query string parameter to mitigate this vulnerability.
Affected versions
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.0-rc5
1.0.0-rc6
+ 59 more
Show less
1.0.0-rc7
1.0.0-rc8
1.0.0-rc9
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.10.0
2.10.1
2.10.2
2.11.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
4.0.0
4.0.1
4.1.0
Updated Jun 17, 2026 · Source: OSV.dev
|
|
- Released
- Mar 08, 2020
- Checksum
-
|
2.0.5
patch
1 CVE
CVE-2026-55590
GHSA-hhpq-7wg4-36jm
Jun 17, 2026
CakePHP Authentication: Open redirect weakness via backslash bypass
Impact
The getLoginRedirect() method contains a weakness to backslash bypasses allowing redirect targets with attacker controlled hostnames.
Patches
3.3.6 and 4.1.1 contain a fix for this issue.
Workarounds
If you are unable to upgrade, you should consider adding application validation to the redirect query string parameter to mitigate this vulnerability.
Affected versions
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.0-rc5
1.0.0-rc6
+ 59 more
Show less
1.0.0-rc7
1.0.0-rc8
1.0.0-rc9
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.10.0
2.10.1
2.10.2
2.11.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
4.0.0
4.0.1
4.1.0
Updated Jun 17, 2026 · Source: OSV.dev
|
|
- Released
- Feb 11, 2020
- Checksum
-
- Funding
-
__unset
|
1.4.2
patch
1 CVE
CVE-2026-55590
GHSA-hhpq-7wg4-36jm
Jun 17, 2026
CakePHP Authentication: Open redirect weakness via backslash bypass
Impact
The getLoginRedirect() method contains a weakness to backslash bypasses allowing redirect targets with attacker controlled hostnames.
Patches
3.3.6 and 4.1.1 contain a fix for this issue.
Workarounds
If you are unable to upgrade, you should consider adding application validation to the redirect query string parameter to mitigate this vulnerability.
Affected versions
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.0-rc5
1.0.0-rc6
+ 59 more
Show less
1.0.0-rc7
1.0.0-rc8
1.0.0-rc9
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.10.0
2.10.1
2.10.2
2.11.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
4.0.0
4.0.1
4.1.0
Updated Jun 17, 2026 · Source: OSV.dev
|
|
- Released
- Jan 25, 2020
- Checksum
-
Dependencies
(3)
-
cakephp/core
^3.7
-
psr/http-message
^1.0
-
zendframework/zend-diactoros
^1.4.0
|
2.0.4
patch
1 CVE
CVE-2026-55590
GHSA-hhpq-7wg4-36jm
Jun 17, 2026
CakePHP Authentication: Open redirect weakness via backslash bypass
Impact
The getLoginRedirect() method contains a weakness to backslash bypasses allowing redirect targets with attacker controlled hostnames.
Patches
3.3.6 and 4.1.1 contain a fix for this issue.
Workarounds
If you are unable to upgrade, you should consider adding application validation to the redirect query string parameter to mitigate this vulnerability.
Affected versions
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.0-rc5
1.0.0-rc6
+ 59 more
Show less
1.0.0-rc7
1.0.0-rc8
1.0.0-rc9
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.10.0
2.10.1
2.10.2
2.11.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
4.0.0
4.0.1
4.1.0
Updated Jun 17, 2026 · Source: OSV.dev
|
|
- Released
- Jan 25, 2020
- Checksum
-
|
2.0.3
patch
1 CVE
CVE-2026-55590
GHSA-hhpq-7wg4-36jm
Jun 17, 2026
CakePHP Authentication: Open redirect weakness via backslash bypass
Impact
The getLoginRedirect() method contains a weakness to backslash bypasses allowing redirect targets with attacker controlled hostnames.
Patches
3.3.6 and 4.1.1 contain a fix for this issue.
Workarounds
If you are unable to upgrade, you should consider adding application validation to the redirect query string parameter to mitigate this vulnerability.
Affected versions
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.0-rc5
1.0.0-rc6
+ 59 more
Show less
1.0.0-rc7
1.0.0-rc8
1.0.0-rc9
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.10.0
2.10.1
2.10.2
2.11.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
4.0.0
4.0.1
4.1.0
Updated Jun 17, 2026 · Source: OSV.dev
|
|
- Released
- Jan 15, 2020
- Checksum
-
|
1.4.1
patch
1 CVE
CVE-2026-55590
GHSA-hhpq-7wg4-36jm
Jun 17, 2026
CakePHP Authentication: Open redirect weakness via backslash bypass
Impact
The getLoginRedirect() method contains a weakness to backslash bypasses allowing redirect targets with attacker controlled hostnames.
Patches
3.3.6 and 4.1.1 contain a fix for this issue.
Workarounds
If you are unable to upgrade, you should consider adding application validation to the redirect query string parameter to mitigate this vulnerability.
Affected versions
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.0-rc5
1.0.0-rc6
+ 59 more
Show less
1.0.0-rc7
1.0.0-rc8
1.0.0-rc9
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.10.0
2.10.1
2.10.2
2.11.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
4.0.0
4.0.1
4.1.0
Updated Jun 17, 2026 · Source: OSV.dev
|
|
- Released
- Dec 17, 2019
- Checksum
-
|
2.0.2
patch
1 CVE
CVE-2026-55590
GHSA-hhpq-7wg4-36jm
Jun 17, 2026
CakePHP Authentication: Open redirect weakness via backslash bypass
Impact
The getLoginRedirect() method contains a weakness to backslash bypasses allowing redirect targets with attacker controlled hostnames.
Patches
3.3.6 and 4.1.1 contain a fix for this issue.
Workarounds
If you are unable to upgrade, you should consider adding application validation to the redirect query string parameter to mitigate this vulnerability.
Affected versions
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.0-rc5
1.0.0-rc6
+ 59 more
Show less
1.0.0-rc7
1.0.0-rc8
1.0.0-rc9
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.10.0
2.10.1
2.10.2
2.11.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
4.0.0
4.0.1
4.1.0
Updated Jun 17, 2026 · Source: OSV.dev
|
|
- Released
- Dec 17, 2019
- Checksum
-
|
2.0.1
patch
1 CVE
CVE-2026-55590
GHSA-hhpq-7wg4-36jm
Jun 17, 2026
CakePHP Authentication: Open redirect weakness via backslash bypass
Impact
The getLoginRedirect() method contains a weakness to backslash bypasses allowing redirect targets with attacker controlled hostnames.
Patches
3.3.6 and 4.1.1 contain a fix for this issue.
Workarounds
If you are unable to upgrade, you should consider adding application validation to the redirect query string parameter to mitigate this vulnerability.
Affected versions
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.0-rc5
1.0.0-rc6
+ 59 more
Show less
1.0.0-rc7
1.0.0-rc8
1.0.0-rc9
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
1.4.0
1.4.1
1.4.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.10.0
2.10.1
2.10.2
2.11.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
4.0.0
4.0.1
4.1.0
Updated Jun 17, 2026 · Source: OSV.dev
|
|
- Released
- Dec 17, 2019
- Checksum
-
|