Junglewise Threat Intelligence

CVE-2025-54576: GO-2025-3833 - OAuth2-Proxy has authentication bypass in oauth2-proxy skip_auth_routes due to Query Parameter inclusion in github.com/oauth2-proxy/oauth2-p

CVE-2025-54576 · Severity: low · CVSS 3.1 · Published 2025-08-11

Technologies: github.com/oauth2-proxy/oauth2-proxy (Go), github.com/oauth2-proxy/oauth2-proxy/v7 (Go). Vendors: Go.

Executive brief

OAuth2-Proxy has authentication bypass in oauth2-proxy skip_auth_routes due to Query Parameter inclusion in github.com/oauth2-proxy/oauth2-proxy

Affected products

  • Go github.com/oauth2-proxy/oauth2-proxy
  • Go github.com/oauth2-proxy/oauth2-proxy/v7

Related threats