Junglewise Threat Intelligence
CVE-2025-64484: GO-2025-4113 - OAuth2-Proxy is vulnerable to header smuggling via underscore leading to potential privilege escalation in github.com/oauth2-proxy/oauth2-pr
CVE-2025-64484 · Severity: low · CVSS 3.1 · Published 2025-11-17
Technologies: github.com/oauth2-proxy/oauth2-proxy (Go), github.com/oauth2-proxy/oauth2-proxy/v7 (Go). Vendors: Go.
Executive brief
OAuth2-Proxy is vulnerable to header smuggling via underscore leading to potential privilege escalation in github.com/oauth2-proxy/oauth2-proxy
Affected products
- Go github.com/oauth2-proxy/oauth2-proxy
- Go github.com/oauth2-proxy/oauth2-proxy/v7