Junglewise Threat Intelligence

CVE-2026-49332: OpenShift oauth-proxy identity impersonation via header smuggling

CVE-2026-49332 · Severity: high · CVSS 8.5 · Published 2026-07-28

Technologies: Red Hat OpenShift Container Platform 4. Vendors: Red Hat.

Executive brief

A security flaw in the OpenShift OAuth Proxy allows an authenticated user with low privileges to impersonate other users, including administrators. The proxy fails to properly clean up specific technical labels (headers) in web requests, which can confuse the backend applications it is supposed to protect. This could lead to unauthorized access to sensitive data or administrative functions within the applications running behind the proxy.

Technical details

A flaw was found in openshift/oauth-proxy where the proxy sets authenticated identity headers using dash-variant keys (e.g., X-Forwarded-User) but fails to strip underscore-variant keys (e.g., X_Forwarded_User) from incoming client requests. Because Go's http.Header treats these as distinct keys while WSGI (Django, Flask, FastAPI) and PHP frameworks normalize both to the same CGI variable (HTTP_X_FORWARDED_USER), an attacker can smuggle a forged identity header. By providing an underscore-variant header, the attacker may override the legitimate identity header set by the proxy when it reaches the upstream application. This enables identity impersonation and potential privilege escalation.

Affected products

  • Red Hat OpenShift Container Platform 4 4
  • OpenShift oauth-proxy

Timeline

  • 2026-05-29: disclosed: Initial report in Red Hat Bugzilla
  • 2026-07-28: advisory: NVD publication date

References