CVE-2026-54915 Overview
CVE-2026-54915 is an open redirect vulnerability in Tautulli, a Python-based monitoring and tracking tool for Plex Media Server. Versions prior to 2.17.2 expose an unauthenticated /auth/redirect endpoint in plexpy/webauth.py that improperly sanitizes the redirect_uri parameter. The code strips forward slashes but leaves tab, line-feed, and carriage-return characters intact. When combined with the default root HTTP_ROOT configuration, CherryPy's HTTPRedirect passes the whitespace-bearing path to urllib.parse.urljoin, which resolves to an attacker-controlled external origin. Instances using custom non-root HTTP_ROOT values are not affected. The issue is fixed in version 2.17.2 [CWE-601].
Critical Impact
Attackers can craft links that redirect Tautulli users to arbitrary external origins for phishing and post-login redirect-flow abuse.
Affected Products
- Tautulli versions prior to 2.17.2
- Deployments using the default root HTTP_ROOT configuration
- The plexpy/webauth.py/auth/redirect endpoint
Discovery Timeline
- 2026-09-21 - CVE-2026-54915 published to the National Vulnerability Database (NVD)
- 2026-09-21 - Last updated in NVD database
Technical Details for CVE-2026-54915
Vulnerability Analysis
The flaw resides in the redirect handler within plexpy/webauth.py. The function accepts a user-controlled redirect_uri parameter and normalizes it by stripping the configured HTTP_ROOT prefix and calling strip('/'). This sanitization removes forward slashes but ignores whitespace control characters such as tab (\t), carriage return (\r), and line feed (\n). The resulting value is concatenated with plexpy.HTTP_ROOT and passed to cherrypy.HTTPRedirect, which internally calls urllib.parse.urljoin. When HTTP_ROOT is the default /, urljoin interprets a value beginning with whitespace followed by //attacker.example as a scheme-relative URL, resolving it to the attacker-controlled origin.
Root Cause
The root cause is insufficient input validation on the redirect_uri parameter. The sanitization logic assumed that removing forward slashes would prevent redirect targets from escaping the local origin. It failed to account for the parsing behavior of urllib.parse.urljoin when presented with whitespace-prefixed URLs, which is a documented URL parsing edge case.
Attack Vector
An unauthenticated remote attacker crafts a malicious URL pointing at a vulnerable Tautulli instance with a redirect_uri value containing whitespace characters and an external target. The victim clicks the link, and the server responds with an HTTP redirect to the attacker's origin. This enables phishing pages that appear to originate from a trusted Tautulli host and can abuse post-authentication redirect flows to hijack session context. User interaction is required, and the attack requires no privileges on the target instance.
return error_message
@cherrypy.expose
+ @requireAuth()
def redirect(self, redirect_uri='', *args, **kwargs):
root = plexpy.HTTP_ROOT.rstrip('/')
if redirect_uri.startswith(root):
redirect_uri = redirect_uri[len(root):]
- raise cherrypy.HTTPRedirect(plexpy.HTTP_ROOT + redirect_uri.strip('/'))
+ raise cherrypy.HTTPRedirect(plexpy.HTTP_ROOT + redirect_uri.strip('/ \t\r\n'))
Source: Tautulli commit 07f9beaa. The patch adds an authentication requirement via @requireAuth() and extends the character stripping to include space, tab, carriage return, and line feed.
Detection Methods for CVE-2026-54915
Indicators of Compromise
- HTTP requests to /auth/redirect containing redirect_uri parameters with URL-encoded whitespace such as %09, %0a, or %0d.
- Access log entries showing /auth/redirect requests with redirect_uri values that reference external hostnames or scheme-relative URLs.
- Referer headers on outbound user traffic pointing to Tautulli /auth/redirect URLs followed by navigation to untrusted domains.
Detection Strategies
- Inspect Tautulli access logs for the /auth/redirect path and flag any redirect_uri parameter values decoding to non-local hosts.
- Deploy WAF or reverse-proxy rules that reject redirect_uri values containing whitespace control characters or protocol-relative prefixes.
- Correlate authentication events with subsequent 3xx redirect responses to detect potential post-login redirect abuse.
Monitoring Recommendations
- Alert on any HTTP 303 or 302 response from /auth/redirect with a Location header pointing outside the configured Tautulli origin.
- Monitor phishing feeds and URL reputation services for domains hosting lookalike Tautulli landing pages.
- Track Tautulli version banners across the environment to identify instances running versions earlier than 2.17.2.
How to Mitigate CVE-2026-54915
Immediate Actions Required
- Upgrade all Tautulli instances to version 2.17.2 or later, which enforces authentication on the redirect endpoint and strips whitespace characters.
- Audit reverse-proxy and WAF configurations to block requests with encoded whitespace in redirect parameters.
- Notify users of the potential for phishing links that leverage the trusted Tautulli hostname.
Patch Information
The fix is available in Tautulli 2.17.2. See the GitHub release notes for v2.17.2 and the GitHub Security Advisory GHSA-7c9r-fhj9-87xm for full details. The patch commit adds @requireAuth() to the redirect handler and expands the strip() call to include space, tab, carriage return, and line-feed characters.
Workarounds
- Configure a non-root HTTP_ROOT value, which prevents urllib.parse.urljoin from resolving the crafted input to an external origin.
- Place Tautulli behind a reverse proxy that rejects requests to /auth/redirect containing whitespace or external hostnames in redirect_uri.
- Restrict access to the Tautulli web interface to trusted networks until the upgrade is applied.
# Upgrade Tautulli via git to the patched release
cd /opt/Tautulli
git fetch --tags
git checkout v2.17.2
systemctl restart tautulli
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.