CVE-2026-40575
oauth2-proxy oauth2-proxy, Red Hat Ceph Storage 9, oauth2 proxy
OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions 7.5.0 through 7.15.1 may trust a client-supplied `X-Forwarded-Uri` header when `--reverse-proxy` is enabled and `--skip-auth-regex` or `--skip-auth-route` is configured. An attacker can spoof this header so OAuth2 Proxy evaluates authentication and skip-auth rules against a different path than the one actually sent to the upstream application. This can result in an unauthenticated remote attacker bypassing authentication and accessing protected routes without a valid session. Impacted users are dep...
- CVSS
- 9.1
- EPSS
- 0.48% 38.7% percentile
- CISA KEV
- Not listed
- Published
- 2026.04.22