GHSA-44p5-3m5g-vfhj

Suggest an improvement
Source
https://github.com/advisories/GHSA-44p5-3m5g-vfhj
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-44p5-3m5g-vfhj/GHSA-44p5-3m5g-vfhj.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-44p5-3m5g-vfhj
Aliases
  • CVE-2026-44745
Published
2026-07-14T03:31:35Z
Modified
2026-09-01T21:40:52Z
Severity
  • 8.1 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N CVSS Calculator
Summary
SAP Approuter has an Open Redirect vulnerability
Details

SAP Approuter does not properly validate incoming request headers during the OAuth2 login flow under certain configurations. This allows an unauthenticated remote attacker to craft a malicious link which, when clicked by a victim, could lead to unauthorized access. Successful exploitation results in a high impact to the confidentiality and integrity with no impact on the availability of the application.

Database specific
{
    "cwe_ids": [
        "CWE-601"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-09-01T21:20:47Z",
    "nvd_published_at": "2026-07-14T01:16:17Z",
    "severity": "HIGH"
}
References

Affected packages

npm / @sap/approuter

Package

Name
@sap/approuter
View open source insights on deps.dev
Purl
pkg:npm/%40sap/approuter

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
21.2.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-44p5-3m5g-vfhj/GHSA-44p5-3m5g-vfhj.json"