← Vulnerability feed

Vulnerability record · CVE-2021-28125 · published 27 April 2021

CVE-2021-28125: Apache Superset URL shortener open redirect

Apache · Superset

Apache Superset up to and including 1.0.1 fails to validate user input in its URL shortener, allowing creation of short links that redirect to attacker-controlled external URLs. Because the short link appears to belong to the trusted Superset instance, it is a credible phishing lure against users of the platform.

6.1 CVSS 3.1 Medium EPSS 64% · top 0.8% CWE-601 · Open redirect
6.1CVSS 3.1 base score, v2 5.8
64%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
10References
17 Jun 2026Last modified by NVD

Description

Apache Superset up to and including 1.0.1 allowed for the creation of an external URL that could be malicious. By not checking user input for open redirects the URL shortener functionality would allow for a malicious user to create a short URL for a dashboard that could convince the user to click the link.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

medium priorityThe flaw is a medium-severity open redirect requiring user interaction with no direct compromise, though the high EPSS score and trusted-domain phishing value warrant prompt patching.

What it is

Apache Superset up to and including 1.0.1 fails to validate user input in its URL shortener, allowing creation of short links that redirect to attacker-controlled external URLs. Because the short link appears to belong to the trusted Superset instance, it is a credible phishing lure against users of the platform.

Impact

An attacker can craft a Superset-hosted short URL that redirects a victim to a malicious site, enabling credential phishing or malware delivery under the guise of a trusted dashboard link. The flaw itself yields no direct data access or code execution.

Attack surface

Reachable over the network through the URL shortener functionality; no authentication is required to create the malicious short URL, but the victim must click the link (UI:R). Scope is changed since the redirect lands on an external origin.

Exploitation

Not listed in CISA KEV and no public exploit references are tagged in the record; EPSS is high at roughly 0.64 (99th percentile), indicating elevated predicted exploitation likelihood despite the absence of confirmed in-the-wild activity.

What to do

  • Upgrade Apache Superset past 1.0.1 to a release that validates redirect targets in the URL shortener.
  • If immediate upgrade is not possible, restrict or disable the URL shortener feature until patched.
  • Enforce an allowlist of permitted redirect destinations and reject external or absolute URLs.
  • Place Superset behind a reverse proxy or web filter that blocks outbound redirects to untrusted domains.
  • Train users not to trust short links, even those on the Superset domain, and verify destinations before clicking.

Detection

  • Monitor Superset URL shortener creation and access logs for short links whose redirect target is an external domain.
  • Alert on HTTP 3xx responses from the Superset host that point to non-allowlisted or newly registered domains.
  • Review proxy and DNS logs for Superset-originated redirects to suspicious external hosts.
  • Correlate user reports of unexpected redirects from Superset short links with shortener log entries.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-28125 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-27524Apache Superset default SECRET_KEY allows session forgery and auth bypassApache Superset versions up to and including 2.0.1 ship with a default SECRET_KEY that, if left unchanged, lets an attacker forge signed session cook…KEVEPSS 97%analysed9.8CVE-2024-39887Apache superset sql injection vulnerabilityAn SQL Injection vulnerability in Apache Superset exists due to improper neutralization of special elements used in SQL commands. Specifically, certa…EPSS 4.4%9.8CVE-2022-27479Apache superset sql injection vulnerabilityApache Superset before 1.4.2 is vulnerable to SQL injection in chart data requests. Users should update to 1.4.2 or higher which addresses this issue.EPSS 2.9%9.8CVE-2018-8021Apache Superset pickle deserialization remote code executionApache Superset versions prior to 0.23 deserialized data with an unsafe pickle load method, allowing untrusted serialized data to be executed as code…EPSS 53%analysed8.8CVE-2023-49736Apache superset sql injection vulnerabilityA where_in JINJA macro allows users to specify a quote, which combined with a carefully crafted statement would allow for SQL injection in Apache Sup…EPSS 1.2%8.8CVE-2023-40610Apache superset incorrect authorization vulnerabilityImproper authorization check and possible privilege escalation on Apache Superset up to but excluding 2.1.2. Using the default examples database conn…EPSS 1.3%8.8CVE-2022-43719Apache superset cross-site request forgery vulnerabilityTwo legacy REST API endpoints for approval and request access are vulnerable to cross site request forgery. This issue affects Apache Superset versio…EPSS 0.57%8.8CVE-2021-41971Apache superset sql injection vulnerabilityApache Superset up to and including 1.3.0 when configured with ENABLE_TEMPLATE_PROCESSING on (disabled by default) allowed SQL injection when a malic…EPSS 1.8%

Source: NIST National Vulnerability Database (record CVE-2021-28125), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.