PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Mar 26, 2026

JumpServer - Open Redirect via Referer Header

Est. Time~10 seconds
Scan TypeGroup Scan
Targetsurl
CostFree
2.1k
Times Used
continuous scan runs
0
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2025-58044
5.5
CVSSmedium
Exploitable remotely over the internet · no authentication required.

JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to v3.10.19 and v4.10.5, The /core/i18n// endpoint uses the Referer header as the redirection target without proper validation, which could lead to an Open Redirect vulnerability. This vulnerability is fixed in v3.10.19 and v4.10.5.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
jumpserverby jumpserver
< 3.10.19
Updated Sep 9, 2026View on NVD →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

JumpServer - Open Redirect via Referer Header CVE-2025-58044 Scanner | S4E