CVE-2025-64484Disclosure

HIGHCVSS 8.5 · HIGH

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

OAuth2-Proxy is an open-source tool that can act as either a standalone reverse proxy or a middleware component integrated into existing reverse proxy or load balancer setups. In versions prior to 7.13.0, all deployments of OAuth2 Proxy in front of applications that normalize underscores to dashes in HTTP headers (e.g., WSGI-based frameworks such as Django, Flask, FastAPI, and PHP applications). Authenticated users can inject underscore variants of X-Forwarded-* headers that bypass the proxy’s filtering logic, potentially escalating privileges in the upstream app. OAuth2 Proxy authentication/authorization itself is not compromised. The problem has been patched with v7.13.0. By default all specified headers will now be normalized, meaning that both capitalization and the use of underscores (_) versus dashes (-) will be ignored when matching headers to be stripped. For example, both `X-Forwarded-For` and `X_Forwarded-for` will now be treated as equivalent and stripped away. For those who have a rational that requires keeping a similar looking header and not stripping it, the maintainers introduced a new configuration field for Headers managed through the AlphaConfig called `InsecureSkipHeaderNormalization`. As a workaround, ensure filtering and processing logic in upstream services don't treat underscores and hyphens in Headers the same way.

7.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-644

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • 6 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 5 classified signals
  • Peaked 2d ago at 2 mentions (2026-03-12); latest day: 2
  • 6 total mentions across 4 days

Deep dive

Activity timeline6 mentions / 4d
01122Mentions · 2026-03-11: 1Mentions · 2026-03-12: 2Mentions · 2026-03-13: 1Mentions · 2026-08-11: 2PoC Mentioned / Linked · 2026-08-11: 1Exploit Tool / Code · 2026-03-11: 1Active Exploitation · 2026-03-13: 1Technical Details · 2026-03-11: 1Technical Details · 2026-03-12: 2Technical Details · 2026-03-13: 103-1103-1203-1308-11
Signal classification2 categories
Disclosure
583.3%
Active Exploitation
116.7%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-111
Disclosure1
2026-03-122
Disclosure2
2026-03-131
Active Exploitation1
2026-08-112
Disclosure2
Full discourse6 posts
  • Praetorian@praetorianlabs
    Disclosure

    Two new CVEs. Two different proxies. One systemic flaw. CVE-2025-48865 (Fabio): Abuse the Connection header → strip X-Forwarded-For → backend's access control never triggers. CVE-2025-64484 (OAuth2-proxy): Send X_Forwarded_Email (underscore) → proxy misses it → Django/Flask normalize it → full auth bypass. Your proxy isn't a trust boundary. It's an attack surface. Full breakdown in the replies ↓ #AppSec #CVE #OffensiveSecurity

    Post summary

    The post announces two newly disclosed CVEs affecting Fabio and OAuth2‑proxy, detailing the core vulnerabilities but providing no evidence of active exploitation, patches, or PoC scripts.

    3301451.4K
    8.5K followersView on X
  • Praetorian@praetorianlabs
    Disclosure

    Two new CVEs. Two different proxies. One systemic flaw. 🔥CVE-2025-48865 (Fabio): Abuse the Connection header → strip X-Forwarded-For → backend's access control never triggers. 🔥CVE-2025-64484 (OAuth2-proxy): Send X_Forwarded_Email (underscore) → proxy misses it → Django/Flask normalize it → full auth bypass. Your proxy isn't a trust boundary. It's an attack surface. Full breakdown 🔗 https://buff.ly/yg75n4T #AppSec #CVE #OffensiveSecurity

    Post summary

    The post announces two newly disclosed CVEs, outlining how specific HTTP header manipulations can bypass access controls in Fabio and OAuth2-proxy.

    010861.0K
    8.6K followersView on X
  • CVE Brief@DailyCVEBrief
    Disclosure

    LOOK BACK — oauth2-proxy stripped X-Forwarded-User. It did not strip X_Forwarded_User. Go says those are different headers; Django, Flask and PHP say they're the same one. That gap is CVE-2025-64484. The technique was published five years earlier. https://t.co/jeNS75ODmY

    Post summary

    The tweet highlights a new CVE-2025-64484 caused by oauth2-proxy's inconsistent handling of X-Forwarded-User headers, referencing an earlier published technique.

    1000056
    26 followersView on X
  • CVE Brief@DailyCVEBrief
    Disclosure

    Full Look Back: the 2016 commit that created the header contract, why an 8.5 score and CISA's "no exploitation" rating are both right, and the sequel CVE in April. https://cvebrief.com/cve/CVE-2025-64484/ https://t.co/Fi8hrhW3cm

    Post summary

    The tweet provides a high‑level disclosure of CVE‑2025‑64484, noting its 8.5 severity score, CISA’s no‑exploitation assessment, and a historical commit context, but offers no details on exploitation, patches, or technical aspects.

    0000037
    26 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis shows attackers exploiting reverse proxy header manipulation vulnerabilities to bypass authentication and escalate privileges. CVE-2025-48865 (Fabio) and CVE-2025-64484 (OAuth2-Proxy) enable injection of crafted headers, leading to lateral movement within compromised networks. Runtime segmentation helps limit blast radius of such post-compromise activity. #CloudSecurity 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/fabio-oauth2-proxy-2025-reverse-proxy-vulnerabilities

    Post summary

    The post reports that CVE‑2025‑48865 and CVE‑2025‑64484 are being actively exploited via reverse‑proxy header manipulation to bypass authentication and enable lateral movement within compromised networks.

    00000166
    1.9K followersView on X
  • Vivek | Cybersecurity@VivekIntel
    Disclosure

    CVE-2025-48865 and CVE-2025-64484 expose how HTTP header manipulation between reverse proxies and backend applications can enable authentication bypass and privilege escalation by exploiting hop-by-hop header stripping and header normalization inconsistencies. https://www.praetorian.com/blog/reverse-proxy-header-attacks/

    Post summary

    The post discloses that CVE‑2025‑48865 and CVE‑2025‑64484 enable authentication bypass and privilege escalation via HTTP header manipulation between reverse proxies and backend applications.

    00000142
    242 followersView on X

Explore more