Authentication Bypass Vulnerability in OAuth2 Proxy by Oauth2-Proxy
⚠️ CVE-Referenzen:
CVE-2026-40575
Oauth2-proxy - Oauth2-proxy - CRITICAL - CVE-2026-40575.
OAuth2 Proxy, a tool for managing authentication using OAuth2 providers, has a vulnerability where affected versions (7.5.0 to 7.15.1) may improperly handle the client-supplied 'X-Forwarded-Uri' header. When 'reverse-proxy' mode is enabled alongside 'skip-auth-regex' or 'skip-auth-route', it allows an attacker to spoof this header. This can lead to the bypassing of authentication mechanisms, permitting unauthorized access to protected resources. Users running specific configurations are strongly encouraged to update to version 7.15.2 or implement essential workarounds to secure their deployments.
Quelle: securityvulnerability.io