CVE-2026-49826: Concourse login flow has an open redirect issue
An attacker is able to craft and send a user a URL that will redirect the user from the Concourse web server to any other site. This could be used in a phishing attack to steal user’s credentials.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-49826 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →