cakephp/authentication
php · cakephp/authenticationHeads-up
cakephp/authentication getLoginRedirect() backslash bypass vulnerability
The `getLoginRedirect()` method had a weakness to backslash bypasses allowing redirect targets with attacker controlled hostnames.
18 Jun 2026 · schedule it