Submission File: ES2604-7d364742-mod-CWE-50-add-relationship.txt
ID: ES2604-7d364742
SUBMISSION DATE: 2026-04-15 08:02:01
NAME: CWE-50 modification add CanPrecede of CWE-601
DESCRIPTION:
We suggest adding a CanPrecede relation of CWE-601. Similarly, CWE-601
should document CanFollow of CWE-50.
Context: There has been multiple open-redirect CVE entries caused by
mistreatment of double slashes in the Location header. Those programs
generally accept user input that is prefixed with a slash, and use it
directly for redirecting purposes. Because double-slash-prefixed URLs are
schema-relative and not origin-relative, this produces open redirect.
Example CVEs: CVE-2025-54793, CVE-2021-23387, CVE-2021-22964,
CVE-2020-28724
Submission File: ES2604-7d364742-mod-CWE-50-add-relationship.txt
ID: ES2604-7d364742
SUBMISSION DATE: 2026-04-15 08:02:01
NAME: CWE-50 modification add CanPrecede of CWE-601
DESCRIPTION:
We suggest adding a CanPrecede relation of CWE-601. Similarly, CWE-601
should document CanFollow of CWE-50.
Context: There has been multiple open-redirect CVE entries caused by
mistreatment of double slashes in the Location header. Those programs
generally accept user input that is prefixed with a slash, and use it
directly for redirecting purposes. Because double-slash-prefixed URLs are
schema-relative and not origin-relative, this produces open redirect.
Example CVEs: CVE-2025-54793, CVE-2021-23387, CVE-2021-22964,
CVE-2020-28724