CVE-2026-40295 | heartcombo devise up to 5.0.3 Timeoutable FailureApp#redirect_url (GHSA-jp94-3292-c3xv / Nessus ID 316558)
A vulnerability identified as problematic has been detected in heartcombo devise up to 5.0.3. This vulnerability affects the function FailureApp#redirect_url of the component Timeoutable Module. This manipulation causes open redirect.
The identification of this vulnerability is CVE-2026-40295. It is possible to initiate the attack remotely. There is no exploit available.
You should upgrade the affected component.