The getLoginRedirect() method contains a weakness to backslash bypasses allowing redirect targets with attacker controlled hostnames.
2.11.1, 3.3.6 and 4.1.1 contain a fix for this issue.
If you are unable to upgrade, you should consider adding application validation to the redirect query string parameter to mitigate this vulnerability.
{
"cwe_ids": [
"CWE-601"
],
"github_reviewed": true,
"github_reviewed_at": "2026-06-17T18:52:09Z",
"nvd_published_at": "2026-07-09T19:17:06Z",
"severity": "MODERATE"
}