Aretiq.AI[verified]@AretiqAIGeneral
The bulletin announces the CVE but supplies no technical, exploit, or mitigation details, indicating a general announcement.
Upwind Security MDR[verified]@UpwindMDRPatch
A critical OAuth2 Proxy authentication bypass (CVE‑2026‑76835) is disclosed, with no fix yet available, but the text provides a workaround by configuring --trusted-proxy‑ip and ensuring upstream proxy rewrites X‑Forwarded‑Uri.
CCB Alert@CCBalertPatch
The advisory highlights a critical authentication bypass in OAuth2-Proxy (CVE-2026-76835) with CVSS 9.1, confirms a patch is available, but does not provide a PoC, exploit code, or evidence of active exploitation.
Hephaestvs@Vulcanux_PoC
The tweet announces a publicly available proof of concept for CVE-2026-76835, describing an authentication bypass and linking to the PoC, while advising to keep systems updated.
Infoflowcloud@infoflowcloudDisclosure
The tweet announces CVE‑2026‑76835, indicating that OAuth2 Proxy incorrectly processes client‑supplied X‑Forwarded‑Uri headers and may allow authentication bypass.
CVE@CVEnewDisclosure
The post describes a flaw in OAuth2 Proxy where the X‑Forwarded‑Uri header can be used to bypass authentication, because the guard from CVE‑2026‑40575 is improperly honored.