โ† All reports

OAuth2 Proxy versions 7.5.0 through 7.15.1 may trust a client-supplied X-Forwarded-Uri header when certain configuration options are enabled, potentially leading to security risks.

CybersecurityTechnologyConflictApr 22, 2026score 0.172 posts ยท 0 replies across 1 instances
The thread discusses two vulnerabilities in the OAuth2 Proxy software, affecting versions 7.5.0 through 7.15.1. These vulnerabilities involve potential trust issues with the X-Forwarded-Uri header and a configuration-dependent authentication bypass, which could impact system security.

Claims

OAuth2 Proxy versions 7.5.0 through 7.15.1 may trust a client-supplied X-Forwarded-Uri header when certain configuration options are enabled, potentially leading to security risks.
Parent: CybersecurityEntity: OAuth2 ProxyImpact: negativeDate: Apr 22, 2026Target: OAuth2 Proxy versions 7.5.0 through 7.15.1 may trust a client-supplied X-Forwarded-Uri header when certain configuration options are enabled, potentially leading to security risks.
OAuth2 Proxy versions 7.5.0 through 7.15.1 have a configuration-dependent authentication bypass, which could be exploited if specific deployment conditions are met.
Parent: CybersecurityEntity: OAuth2 ProxyImpact: negativeDate: Apr 22, 2026Target: OAuth2 Proxy versions 7.5.0 through 7.15.1 have a configuration-dependent authentication bypass, which could be exploited if specific deployment conditions are met.

Source posts

@[email protected]
๐Ÿšจ EUVD-2026-24559 ๐Ÿ“Š Score: 8.2/10 (CVSS v3.1) ๐Ÿ“ฆ Product: oauth2-proxy ๐Ÿข Vendor: oauth2-proxy ๐Ÿ“… Updated: 2026-04-21 ๐Ÿ“ OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions 7.5.0 through 7.15.1 have a configuration-dependent authentication bypass. Deployments are affected when all of the following are true: Use of `skip_auth_... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24559 #cybersecurity #infosec #euvd #cve #vulnerability
1 boosts ยท 0 favs ยท 0 replies ยท Apr 22, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
๐Ÿšจ EUVD-2026-24557 ๐Ÿ“Š Score: 9.1/10 (CVSS v3.1) ๐Ÿ“ฆ Product: oauth2-proxy ๐Ÿข Vendor: oauth2-proxy ๐Ÿ“… Updated: 2026-04-21 ๐Ÿ“ OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions 7.5.0 through 7.15.1 may trust a client-supplied `X-Forwarded-Uri` header when `--reverse-proxy` is enabled and `--skip-auth-regex` or `--skip-auth-route`... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24557 #cybersecurity #infosec #euvd #cve #vulnerability
1 boosts ยท 0 favs ยท 0 replies ยท Apr 22, 2026
#cybersecurity#infosec#euvd#cve#vulnerability