In WordPress before 5.2.3, validation and sanitization of a URL in wpvalidateredirect in wp-includes/pluggable.php could lead to an open redirect if a provided URL path does not start with a forward slash.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-16220.json"