CVE-2026-41059Disclosure(oauth2_proxy_project / oauth2_proxy)

LOWCVSS 8.2 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions 7.5.0 through 7.15.1 have a configuration-dependent authentication bypass. Deployments are affected when all of the following are true: Use of `skip_auth_routes` or the legacy `skip_auth_regex`; use of patterns that can be widened by attacker-controlled suffixes, such as `^/foo/.*/bar$` causing potential exposure of `/foo/secret`; and protected upstream applications that interpret `#` as a fragment delimiter or otherwise route the request to the protected base path. In deployments that rely on these settings, an unauthenticated attacker can send a crafted request containing a number sign in the path, including the browser-safe encoded form `%23`, so that OAuth2 Proxy matches a public allowlist rule while the backend serves a protected resource. Deployments that do not use these skip-auth options, or that only allow exact public paths with tightly scoped method and path rules, are not affected. A fix has been implemented in version 7.15.2 to normalize request paths more conservatively before skip-auth matching so fragment content does not influence allowlist decisions. Users who cannot upgrade immediately can reduce exposure by tightening or removing `skip_auth_routes` and `skip_auth_regex` rules, especially patterns that use broad wildcards across path segments. Recommended mitigations include replacing broad rules with exact, anchored public paths and explicit HTTP methods; rejecting requests whose path contains `%23` or `#` at the ingress, load balancer, or WAF level; and/or avoiding placing sensitive application paths behind broad `skip_auth_routes` rules.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-288

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • oauth2_proxy

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-04-25)
  • 3 total mentions across 2 days

Affected systems

Products
oauth2_proxy

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-22: 1Mentions · 2026-04-25: 2Technical Details · 2026-04-22: 1Technical Details · 2026-04-25: 204-2204-25
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-221
Disclosure1
2026-04-252
Disclosure2
Full discourse3 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-41059 OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions 7.5.0 through 7.15.1 have a configuration-dependent authentication bypas… https://www.cve.org/CVERecord?id=CVE-2026-41059 ----- Traducción: CVE-2026-41059 OAu… http://infoflow.cloud`

    Post summary

    The post announces an authentication bypass in OAuth2 Proxy versions 7.5.0‑7.15.1, providing only the affected versions and the nature of the flaw, without any indication of exploitation or remediation.

    0000046
    72 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-41059 OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions 7.5.0 through 7.15.1 have a configuration-dependent authentication bypas… https://www.cve.org/CVERecord?id=CVE-2026-41059

    Post summary

    CVE‑2026‑41059 exposes a configuration‑dependent authentication bypass in OAuth2 Proxy 7.5.0–7.15.1; details are available through the provided CVE record link.

    00000163
    57.3K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-41059 Configuration-Dependent Authentication Bypass in OAuth2 Proxy Versions 7.5.0-7.15.1 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-41059

    Post summary

    The snippet announces a new authentication bypass vulnerability (CVE-2026-41059) in OAuth2 Proxy versions 7.5.0-7.15.1, providing limited technical details but no PoC, exploit, patch, or active exploitation information.

    0000039
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appoauth2_proxy_projectoauth2_proxy---

Explore more