{"id":"GHSA-44p5-3m5g-vfhj","summary":"SAP Approuter has an Open Redirect vulnerability","details":"SAP Approuter does not properly validate incoming request headers during the OAuth2 login flow under certain configurations. This allows an unauthenticated remote attacker to craft a malicious link which, when clicked by a victim, could lead to unauthorized access. Successful exploitation results in a high impact to the confidentiality and integrity with no impact on the availability of the application.","aliases":["CVE-2026-44745"],"modified":"2026-09-01T21:40:52.202902Z","published":"2026-07-14T03:31:35Z","database_specific":{"github_reviewed_at":"2026-09-01T21:20:47Z","nvd_published_at":"2026-07-14T01:16:17Z","cwe_ids":["CWE-601"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44745"},{"type":"WEB","url":"https://me.sap.com/notes/3741519"},{"type":"WEB","url":"https://url.sap/sapsecuritypatchday"}],"affected":[{"package":{"name":"@sap/approuter","ecosystem":"npm","purl":"pkg:npm/%40sap/approuter"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"21.2.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-44p5-3m5g-vfhj/GHSA-44p5-3m5g-vfhj.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"}]}