Executive brief
OAuth2 Proxy is a reverse proxy that enforces authentication before allowing access to protected applications. An unauthenticated attacker can bypass this protection by supplying a forged X-Forwarded-Uri HTTP header that matches an allowed authentication-skip route, causing the proxy to permit access to protected upstream services. The proxy grants all clients "trusted proxy" status by default, making every external request eligible for header spoofing.
Technical details
OAuth2 Proxy validates whether a request should skip authentication by comparing the request path against a skip-auth allow list (skip_auth_routes and skip_auth_regex). However, GetRequestURI in pkg/requests/util/util.go prefers the X-Forwarded-Uri header over the actual request URI when CanTrustForwardedHeaders returns true. The CanTrustForwardedHeaders function in pkg/apis/middleware/scope.go treats a caller as a trusted proxy if its address is in the TrustedProxies set, which defaults to 0.0.0.0/0 and ::/0 when reverse proxy mode is enabled without explicit trusted_proxy_ip configuration. This means every network client is considered trusted. An attacker sends a request to a protected path while setting X-Forwarded-Uri to a value matching an allow-listed route; the authentication skip decision is made against the spoofed header value, but the upstream service receives the actual protected path unchanged, resulting in unauthorized access. The fix for CVE-2026-40575 is ineffective in the default configuration.
Affected products
- OAuth2 Proxy OAuth2 Proxy before fix for CVE-2026-76835
Timeline
- 2026-08-24: disclosed