Cyber Posture

CWE · MITRE source

CWE-601URL Redirection to Untrusted Site ('Open Redirect')

Abstraction: Base · CVEs in our corpus: 1,458

The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.

Last updated: 09 May 2026 03:25 UTC

NIST 800-53 r5 controls that address this weakness (2)AI

Control Title Family Why it addresses this CWE
AT-2Literacy Training and AwarenessATSecurity awareness includes verifying URLs and avoiding untrusted redirects that lead to malicious sites.
SI-10Information Input ValidationSIValidates redirect targets and URLs to ensure they conform to allowed destinations.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2016-53856.58.10.81352016-07-19
CVE-2021-296226.56.50.86662021-05-19
CVE-2021-36546.56.10.88372022-03-02
CVE-2017-10001176.38.80.76432017-10-05
CVE-2019-100985.96.10.77402019-09-25
CVE-2018-117845.84.30.82622018-10-04
CVE-2020-151295.86.10.76842020-07-30
CVE-2020-115295.46.10.70302020-04-04
CVE-2022-400835.49.60.58772022-09-28
CVE-2020-245505.26.10.65892021-03-31
CVE-2024-222435.28.10.59592024-02-23
CVE-2023-320685.04.70.67102023-05-15
CVE-2024-222595.08.10.56392024-03-16
CVE-2019-72754.86.10.59822019-07-01
CVE-2023-240444.86.10.59152023-01-22
CVE-2020-110344.76.10.58712020-05-05
CVE-2024-11834.66.50.55052024-04-16
CVE-2005-04204.50.00.74712005-04-27
CVE-2020-85594.46.40.51202020-07-22
CVE-2021-463794.46.10.52242022-03-04
CVE-2023-63894.46.10.52522024-01-29
CVE-2023-334054.36.10.51402023-06-21
CVE-2024-228914.39.80.39432024-03-01
CVE-2012-0518 KEV4.24.70.20902012-10-16
CVE-2022-01654.26.10.49042022-03-14