{"id":"CVE-2026-91165","summary":"Warpgate: Markup injection in SSO form_post return page via unencoded redirect/error values","details":"Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.27.6, the response_mode=form_post SSO return path in warpgate-protocol-http/src/api/sso_provider_list.rs uses serde_json::to_string inside ReturnToSsoPostResponse without neutralizing a script-closing sequence. The vulnerable value can enter the script block through the attacker-controlled next redirect parameter stored by warpgate-protocol-http/src/api/sso_provider_detail.rs or through IdP-derived error messages that make_redirect_url concatenates without URL encoding. The IdP-derived path is reachable when the attacker controls a configured identity provider, or when the attacker controls the email or username claim on an attacker-controlled account and the configured identity provider permits the required unvalidated claim format. A victim must complete the form_post SSO flow for the injected markup to be rendered. The Warpgate Content-Security-Policy blocks injected JavaScript and event handlers, so the demonstrated impact is content spoofing, a false login form, or a meta refresh rather than script execution. This issue is fixed in version 0.27.6.","aliases":["GHSA-vvpj-p7j8-4rv4"],"modified":"2026-09-23T03:47:29.423293124Z","published":"2026-09-21T18:53:03.854Z","database_specific":{"cwe_ids":["CWE-79"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/91xxx/CVE-2026-91165.json","cna_assigner":"GitHub_M"},"references":[{"type":"WEB","url":"https://github.com/warp-tech/warpgate/releases/tag/v0.27.6"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/91xxx/CVE-2026-91165.json"},{"type":"ADVISORY","url":"https://github.com/warp-tech/warpgate/security/advisories/GHSA-vvpj-p7j8-4rv4"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-91165"},{"type":"FIX","url":"https://github.com/warp-tech/warpgate/commit/e94425a08f501383a67316673749dcbd637c6ce3"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/warp-tech/warpgate","events":[{"introduced":"0"},{"fixed":"e94425a08f501383a67316673749dcbd637c6ce3"},{"fixed":"3f166ef2fb27d3e6785df315fdc39914f0568404"}],"database_specific":{"source":["AFFECTED_FIELD","REFERENCES"],"extracted_events":[{"introduced":"0"},{"fixed":"0.27.6"}]}}],"versions":["v0.27.5","v0.27.4","v0.27.3","v0.27.2","v0.27.1","chart-v0.0.7","v0.27.0","v0.27.0-beta.5","v0.27.0-beta.4","v0.27.0-beta.3","v0.27.0-beta.2","chart-v0.0.6","v0.27.0-beta.1","v0.26.0","v0.26.0-beta.1","v0.25.5","v0.25.4","v0.25.3","v0.25.2","v0.25.1","v0.25.0","v0.24.0","chart-v0.0.5","v0.23.4","v0.23.3","v0.23.2","v0.23.1","v0.23.0","chart-v0.0.4","0.22.0-dl","v0.22.0-beta.6","v0.22.0-beta.5","v0.22.0-beta.4","v0.22.0-beta.3","chart-v0.0.3","chart-v0.0.2","v0.22.0-beta.2","v0.22.0-beta.1","v0.21.1","v0.21.0","v0.20.2","v0.20.1","v0.20.0","v0.19.1","v0.19.0","v0.18.0","v0.17.0","v0.16.0","v0.15.0","v0.15.0-beta.2","v0.15.0-beta.1","v0.14.1","v0.14.0","v0.14.0-beta.3","v0.14.0-beta.2","v0.14.0-beta.1","v0.13.2","v0.13.1","v0.13.0","v0.13.0-beta.2","v0.13.0-beta.1","v0.12.0","v0.12.0-beta.2","v0.12.0-beta.1","v0.11.0","v0.10.2","v0.10.1","v0.10.0","v0.9.1","v0.9.0","v0.8.1","v0.8.0","v0.7.4","v0.7.3","v0.7.2","v0.7.1","v0.7.0","v0.6.6","v0.6.5","v0.6.4","v0.6.3","v0.6.2","v0.6.1","v0.5.0","v0.4.0","v0.3.0","v0.2.0","v0.2.2","v0.2.1","v0.1.1","v0.1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-91165.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N"}]}