OAuth2 Proxy versions 7.5.0 through 7.15.1 may trust a client-supplied X-Forwarded-Uri header when certain configuration options are enabled, potentially leading to security risks.
Claims
OAuth2 Proxy versions 7.5.0 through 7.15.1 may trust a client-supplied X-Forwarded-Uri header when certain configuration options are enabled, potentially leading to security risks.
Parent: CybersecurityEntity: OAuth2 ProxyImpact: negativeDate: Apr 22, 2026Target: OAuth2 Proxy versions 7.5.0 through 7.15.1 may trust a client-supplied X-Forwarded-Uri header when certain configuration options are enabled, potentially leading to security risks.
OAuth2 Proxy versions 7.5.0 through 7.15.1 have a configuration-dependent authentication bypass, which could be exploited if specific deployment conditions are met.
Parent: CybersecurityEntity: OAuth2 ProxyImpact: negativeDate: Apr 22, 2026Target: OAuth2 Proxy versions 7.5.0 through 7.15.1 have a configuration-dependent authentication bypass, which could be exploited if specific deployment conditions are met.
Source posts
๐จ EUVD-2026-24559
๐ Score: 8.2/10 (CVSS v3.1)
๐ฆ Product: oauth2-proxy
๐ข Vendor: oauth2-proxy
๐
Updated: 2026-04-21
๐ OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions 7.5.0 through 7.15.1 have a configuration-dependent authentication bypass. Deployments are affected when all of the following are true: Use of `skip_auth_...
๐ https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24559
#cybersecurity #infosec #euvd #cve #vulnerability
1 boosts ยท 0 favs ยท 0 replies ยท Apr 22, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
๐จ EUVD-2026-24557
๐ Score: 9.1/10 (CVSS v3.1)
๐ฆ Product: oauth2-proxy
๐ข Vendor: oauth2-proxy
๐
Updated: 2026-04-21
๐ OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions 7.5.0 through 7.15.1 may trust a client-supplied `X-Forwarded-Uri` header when `--reverse-proxy` is enabled and `--skip-auth-regex` or `--skip-auth-route`...
๐ https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24557
#cybersecurity #infosec #euvd #cve #vulnerability
1 boosts ยท 0 favs ยท 0 replies ยท Apr 22, 2026
#cybersecurity#infosec#euvd#cve#vulnerability