CVE-2026-34847 is a DOM-based open redirect vulnerability affecting Hoppscotch, an open-source API development ecosystem, specifically on its /enter page in versions prior to 2026.3.0. The flaw allows an unvalidated redirect query parameter to be used to construct a URL, potentially redirecting users to malicious sites. Rated as Medium severity (CVSS 4.7), this vulnerability has a network attack vector and low complexity, requiring user interaction to exploit, with a potential impact on integrity. There is currently no evidence of active exploitation, nor are public exploit modules or significant community discussion and media coverage available for this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2026.3.0CPE matchmatch criteria | cpe:2.3:a:hoppscotch:hoppscotch:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.