Open redirect in TerriaJS-Server - CVE-2026-77627
Published: September 15, 2026
Vulnerability details
The vulnerability allows a remote attacker to redirect victims to an attacker-controlled site.
The vulnerability exists due to improper validation of redirect targets in the redirectToHttps HTTP-to-HTTPS redirect middleware when processing requests with attacker-controlled Host headers. A remote attacker can send a request with a crafted Host header to poison a shared cache with a malicious redirect.
Exploitation requires a shared cache or CDN that caches 301 responses by path without including Host in its cache key.