Executive brief
OAuth2 Proxy, a tool used to provide authentication for web applications, contains a flaw that allows attackers to bypass security checks. By sending specially crafted web requests, an unauthorized user can trick the system into granting access to protected areas without a valid login. This could lead to the exposure of sensitive internal data or unauthorized access to corporate applications.
Technical details
An authentication bypass (CWE-290) exists in OAuth2 Proxy due to improper handling of the X-Forwarded-Uri header. When the --reverse-proxy flag is enabled alongside --skip_auth_routes or --skip-auth-regex, the application may trust client-supplied headers to evaluate authentication rules. An unauthenticated remote attacker can spoof this header to make the proxy believe the request is for a path that does not require authentication, while the request is actually forwarded to a protected upstream path. The issue is addressed in version 7.15.2 by introducing the --trusted-proxy-ip flag to restrict which source IPs can provide forwarded headers.
Affected products
- OAuth2 Proxy OAuth2 Proxy >= 7.5.0, < 7.15.2
Timeline
- 2026-04-14: disclosed: Reported to oauth2-proxy/oauth2-proxy
- 2026-04-15: advisory: GitHub Advisory published
- 2026-04-22: other: Published to NVD