CVE-2026-40575Disclosure(oauth2_proxy_project / oauth2_proxy)

LOWCVSS 9.1 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch oauth2_proxy_project oauth2_proxy systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions 7.5.0 through 7.15.1 may trust a client-supplied `X-Forwarded-Uri` header when `--reverse-proxy` is enabled and `--skip-auth-regex` or `--skip-auth-route` is configured. An attacker can spoof this header so OAuth2 Proxy evaluates authentication and skip-auth rules against a different path than the one actually sent to the upstream application. This can result in an unauthenticated remote attacker bypassing authentication and accessing protected routes without a valid session. Impacted users are deployments that run oauth2-proxy with `--reverse-proxy` enabled and configure at least one `--skip-auth-regex` or `--skip-auth-route` rule. This issue is patched in `v7.15.2`. Some workarounds are available for those who cannot upgrade immediately. Strip any client-provided `X-Forwarded-Uri` header at the reverse proxy or load balancer level; explicitly overwrite `X-Forwarded-Uri` with the actual request URI before forwarding requests to OAuth2 Proxy; restrict direct client access to OAuth2 Proxy so it can only be reached through a trusted reverse proxy; and/or remove or narrow `--skip-auth-regex` / `--skip-auth-route` rules where possible. For nginx-based deployments, ensure `X-Forwarded-Uri` is set by nginx and not passed through from the client.

0.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-290

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • oauth2_proxy

Threat summary

  • Patch or workaround signal is available
  • 12 mentions across 8 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 11 signals
  • Disclosure: 9 classified signals
  • General: 1 classified signal
  • Peaked 7d ago at 2 mentions (2026-04-16); latest day: 1
  • 12 total mentions across 8 days

Affected systems

Products
oauth2_proxy

Deep dive

Activity timeline12 mentions / 8d
01122Mentions · 2026-04-16: 2Mentions · 2026-04-21: 1Mentions · 2026-04-22: 2Mentions · 2026-04-24: 1Mentions · 2026-04-25: 2Mentions · 2026-08-24: 2Mentions · 2026-08-25: 1Mentions · 2026-08-26: 1Patch / Workaround · 2026-04-16: 1Patch / Workaround · 2026-04-22: 1Patch / Workaround · 2026-08-25: 1Technical Details · 2026-04-16: 2Technical Details · 2026-04-21: 1Technical Details · 2026-04-22: 2Technical Details · 2026-04-24: 1Technical Details · 2026-04-25: 2Technical Details · 2026-08-24: 2Technical Details · 2026-08-25: 104-1604-2104-2204-2404-2508-2408-2508-26
Signal classification3 categories
Disclosure
975.0%
Patch
216.7%
General
18.3%
Referenced assets12 URLs
Classification over time
DateTotalLabels
2026-04-162
Disclosure1Patch1
2026-04-211
Disclosure1
2026-04-222
General1Patch1
2026-04-241
Disclosure1
2026-04-252
Disclosure2
2026-08-242
Disclosure2
2026-08-251
Disclosure1
2026-08-261
Disclosure1
Full discourse12 posts
  • CERT-PY@CERTpy
    Disclosure

    ⚠️ Vulnerabilidad en productos Nginx ❗ CVE-2026-40575 ➡️ Más info: https://www.cert.gov.py/vulnerabilidad-en-productos-nginx-2/ https://t.co/mZz0hS0Qhx

    Post summary

    CERT announced a vulnerability (CVE‑2026‑40575) affecting Nginx products; detailed information is available via the provided link.

    00011240
    6.7K followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨Critical - OAuth2 Proxy authentication bypass via X-Forwarded-Uri under default trusted-proxy set (CVE-2026-76835) buildTrustedProxyNetSet defaults to 0.0.0.0/0 and ::/0 when reverse-proxy mode runs without trusted_proxy_ip, so GetRequestURI trusts a client-supplied X-Forwarded-Uri from anyone. An unauthenticated attacker requests a protected path while spoofing the header to match skip_auth_routes/skip_auth_regex. Incomplete fix for CVE-2026-40575. 👉Affected: oauth2-proxy 7.15.2–7.15.4 | No fix yet — set an explicit --trusted-proxy-ip and have the upstream proxy overwrite X-Forwarded-Uri

    Post summary

    A new OAuth2 Proxy authentication bypass CVE‑2026‑76835 is disclosed; no active exploitation or PoC is reported, but a workaround is provided to mitigate the issue.

    0001092
    294 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    `OAuth2 Proxy` has an authentication bypass vulnerability (CVE-2026-40575) via `X-Forwarded-Uri` header spoofing, potentially leading to unauthorized access. Monitor for updates. #OAuth2Proxy #AuthBypass #infosec https://www.pulsepatch.io/posts/cve-2026-40575-oauth2-proxy-auth-bypass

    Post summary

    The post announces CVE-2026-40575 in OAuth2 Proxy, detailing an authentication bypass through X‑Forwarded‑Uri header spoofing, and advises monitoring for updates but does not provide a PoC, patch, or exploit evidence.

    0000161
    12 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-76835 OAuth2 Proxy honours a client-supplied X-Forwarded-Uri header when deciding whether a request may skip authentication, because the guard added for CVE-2026-40575 is i… https://www.cve.org/CVERecord?id=CVE-2026-76835 ----- Traducción: CVE-2026-76835 OAu… https://infoflow.cloud`

    Post summary

    The post provides a brief disclosure of CVE‑2026‑76835, describing how OAuth2 Proxy incorrectly honors the X‑Forwarded‑Uri header to bypass authentication, but does not mention PoC, exploit code, patches, or evidence of active exploitation.

    0000033
    102 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-76835 OAuth2 Proxy honours a client-supplied X-Forwarded-Uri header when deciding whether a request may skip authentication, because the guard added for CVE-2026-40575 is i… https://www.cve.org/CVERecord?id=CVE-2026-76835

    Post summary

    The text announces CVE‑2026‑76835, describing a flaw where OAuth2 Proxy trusts a client‑supplied X‑Forwarded‑Uri header to bypass authentication.

    000001.5K
    58.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-40575 OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions 7.5.0 through 7.15.1 may trust a client-supplied `X-Forwarded-Uri` heade… https://www.cve.org/CVERecord?id=CVE-2026-40575 ----- Traducción: CVE-2026-40575 OAu… http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-40575, noting that OAuth2 Proxy versions 7.5.0–7.15.1 incorrectly trust the client‑supplied X‑Forwarded‑Uri header; a link to the CVE record is provided.

    0000051
    72 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-40575 OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions 7.5.0 through 7.15.1 may trust a client-supplied `X-Forwarded-Uri` heade… https://www.cve.org/CVERecord?id=CVE-2026-40575

    Post summary

    A vulnerability in OAuth2 Proxy versions 7.5.0–7.15.1 is disclosed, wherein a client‑supplied X-Forwarded-Uri header may be trusted, potentially leading to security issues.

    00000170
    57.3K followersView on X
  • ALL IT Services@ALLITAustralia
    Patch

    Critical OAuth2 Proxy bug (CVE-2026-40575, CVSS 9.1) lets attackers bypass login via a spoofed header. Patch to 7.15.2 today. #AusIT https://allitservices.com.au/oauth2-proxy-hit-by-critical-auth-bypass-patch-cve-2026-40575-now/

    Post summary

    A critical CVE-2026-40575 in OAuth2 Proxy allows attackers to bypass the login by spoofing headers; a patch to version 7.15.2 has been released today.

    0000059
    16 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-40575 X-Forwarded-Uri Header Spoofing Authentication Bypass in ... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-40575 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    The post identifies CVE‑2026‑40575 as an X‑Forwarded‑Uri header spoofing authentication bypass, linking to a details page, but offers no PoC, exploit code, patch, or evidence of active exploitation.

    0000056
    4.0K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-40575: OAuth2 Proxy has an Authenticati... Header injection meets auth bypass - spoofing X-Forwarded-Uri lets attackers dance around skip-auth rules and hit prote... https://zerodaysignal.com/vulnerability/CVE-2026-40575 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces a newly disclosed OAuth2 Proxy vulnerability (CVE-2026-40575) that allows attackers to bypass authentication through header injection using spoofed X-Forwarded-Uri.

    0000079
    218 followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: Critical authentication bypass in #OAuth2 proxy CVE-2026-40575 CVSS: 9.1. A remote attacker can spoof headers to access protected routes without authorization over the network without user interaction. https://ccb.belgium.be/advisories/warning-critical-authentication-bypass-oauth2-can-lead-unauthorized-data-access-patch #Patch #Patch #Patch

    Post summary

    The announcement highlights a critical authentication bypass in OAuth2 proxy (CVE-2026-40575) and directs readers to a patch advisory; no PoC, exploit code, or active exploitation is mentioned.

    00000174
    7.2K followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 OAuth2 Proxy, Authentication Bypass, #CVE-2026-40575 (Critical) https://dailycve.com/oauth2-proxy-authentication-bypass-cve-2026-40575-critical/

    Post summary

    The text announces the CVE-2026-40575 vulnerability with a brief description of an authentication bypass and links to a source, but provides no further technical, exploit, or mitigation details.

    0000034
    181 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appoauth2_proxy_projectoauth2_proxy---

Explore more