Junglewise Threat Intelligence

CVE-2026-34457: OAuth2 Proxy authentication bypass via health check User-Agent spoofing

CVE-2026-34457 · Severity: critical · CVSS 9.1 · Published 2026-04-14

Technologies: github.com/oauth2-proxy/oauth2-proxy (Go), OAuth2 Proxy, github.com/oauth2-proxy/oauth2-proxy/v7 (Go). Vendors: Go, OAuth2 Proxy.

Executive brief

OAuth2 Proxy, a tool used to secure web applications by requiring login via providers like Google or GitHub, contains a flaw that allows attackers to bypass security checks. By mimicking a specific "User-Agent" string used for system health monitoring, an unauthorized user can gain full access to protected internal resources without logging in. This could lead to the exposure of sensitive customer data or unauthorized access to internal corporate tools.

Technical details

An authentication bypass exists in OAuth2 Proxy versions prior to 7.15.2 due to improper validation of health check requests. When configured with an auth_request-style integration (e.g., Nginx auth_request) and either --ping-user-agent or --gcp-healthchecks enabled, the proxy incorrectly treats any request containing the designated health check User-Agent as a valid, authenticated session. This occurs regardless of the requested URL path. An unauthenticated remote attacker can exploit this by spoofing the User-Agent header to match the configured health check string, thereby bypassing the OAuth2 flow and accessing upstream protected resources. The issue is resolved in version 7.15.2.

Affected products

  • OAuth2 Proxy Project OAuth2 Proxy < 7.15.2

Timeline

  • 2026-04-14: disclosed
  • 2026-04-14: patched: Fixed in version 7.15.2
  • 2026-04-14: advisory

References

Related threats