Upwind Security MDR[verified]@UpwindMDRDisclosure
A new OAuth2 Proxy authentication bypass CVE‑2026‑76835 is disclosed; no active exploitation or PoC is reported, but a workaround is provided to mitigate the issue.
CERT-PY@CERTpyDisclosure
CERT announced a vulnerability (CVE‑2026‑40575) affecting Nginx products; detailed information is available via the provided link.
PulsePatch.io@pulsepatchioDisclosure
The post announces CVE-2026-40575 in OAuth2 Proxy, detailing an authentication bypass through X‑Forwarded‑Uri header spoofing, and advises monitoring for updates but does not provide a PoC, patch, or exploit evidence.
Infoflowcloud@infoflowcloudDisclosure
The post provides a brief disclosure of CVE‑2026‑76835, describing how OAuth2 Proxy incorrectly honors the X‑Forwarded‑Uri header to bypass authentication, but does not mention PoC, exploit code, patches, or evidence of active exploitation.
CVE@CVEnewDisclosure
The text announces CVE‑2026‑76835, describing a flaw where OAuth2 Proxy trusts a client‑supplied X‑Forwarded‑Uri header to bypass authentication.
Infoflowcloud@infoflowcloudDisclosure
The post announces CVE-2026-40575, noting that OAuth2 Proxy versions 7.5.0–7.15.1 incorrectly trust the client‑supplied X‑Forwarded‑Uri header; a link to the CVE record is provided.
CVE@CVEnewDisclosure
A vulnerability in OAuth2 Proxy versions 7.5.0–7.15.1 is disclosed, wherein a client‑supplied X-Forwarded-Uri header may be trusted, potentially leading to security issues.
ALL IT Services@ALLITAustraliaPatch
A critical CVE-2026-40575 in OAuth2 Proxy allows attackers to bypass the login by spoofing headers; a patch to version 7.15.2 has been released today.