
Two new CVEs. Two different proxies. One systemic flaw. CVE-2025-48865 (Fabio): Abuse the Connection header → strip X-Forwarded-For → backend's access control never triggers. CVE-2025-64484 (OAuth2-proxy): Send X_Forwarded_Email (underscore) → proxy misses it → Django/Flask normalize it → full auth bypass. Your proxy isn't a trust boundary. It's an attack surface. Full breakdown in the replies ↓ #AppSec #CVE #OffensiveSecurity
Post summary
The post announces two new CVEs for Fabio and OAuth2‑proxy, explaining that header manipulation can bypass backend access controls, with no mention of active attacks, patches, or exploit tools.


