Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-12071

Gravedad CVSS v4.0:
MEDIA
Tipo:
CWE-601 Redireccionamiento de URL a sitio no confiable (Open Redirect)
Fecha de publicación:
07/08/2026
Última modificación:
07/08/2026

Descripción

*** Pendiente de traducción *** The Webbox of TeamDavid by Tobit Laboratories AG constructs redirect URLs using user-supplied input, <br /> which is appended to the redirect target in a 302 HTTP response. By <br /> using URL-encoded characters such as “%2e” (representing a dot), an <br /> attacker can manipulate the portion of the URL following the top-level <br /> domain (TLD). If a similar, registerable TLD exists (for example, if <br /> “.com” is the application’s domain, and “.company” is available for <br /> registration), an attacker can craft a URL to redirect users to a <br /> malicious “.company” domain. By using URL-encoded line feeds, it becomes<br /> possible to insert arbitrary response headers in the server&amp;#39;s HTTP <br /> response.<br /> <br /> <br /> <br /> This issue affects TeamDavid through Rollout 524.