Junglewise Threat Intelligence

CVE-2026-40575: OAuth2 Proxy authentication bypass via X-Forwarded-Uri spoofing

CVE-2026-40575 · Severity: critical · CVSS 9.1 · Published 2026-04-22

Technologies: OAuth2 Proxy, github.com/oauth2-proxy/oauth2-proxy/v7 (Go). Vendors: OAuth2 Proxy, Go.

Executive brief

OAuth2 Proxy, a tool used to provide authentication for web applications, contains a flaw that allows attackers to bypass security checks. By sending specially crafted web requests, an unauthorized user can trick the system into granting access to protected areas without a valid login. This could lead to the exposure of sensitive internal data or unauthorized access to corporate applications.

Technical details

An authentication bypass (CWE-290) exists in OAuth2 Proxy due to improper handling of the X-Forwarded-Uri header. When the --reverse-proxy flag is enabled alongside --skip_auth_routes or --skip-auth-regex, the application may trust client-supplied headers to evaluate authentication rules. An unauthenticated remote attacker can spoof this header to make the proxy believe the request is for a path that does not require authentication, while the request is actually forwarded to a protected upstream path. The issue is addressed in version 7.15.2 by introducing the --trusted-proxy-ip flag to restrict which source IPs can provide forwarded headers.

Affected products

  • OAuth2 Proxy OAuth2 Proxy >= 7.5.0, < 7.15.2

Timeline

  • 2026-04-14: disclosed: Reported to oauth2-proxy/oauth2-proxy
  • 2026-04-15: advisory: GitHub Advisory published
  • 2026-04-22: other: Published to NVD

References

Related threats