CRITICAL
oauth2-proxy
CVE published 2026-08-24
CVE-2026-76835
An authentication bypass vulnerability exists in OAuth2 Proxy due to improper handling of the X-Forwarded-Uri header. This allows an unauthenticated attacker to access protected upstream paths by spoofing the URI, potentially leading to unauthorized access. The vulnerability arises from OAuth2 Proxy's default configuration, which trusts all proxies. An attacker can bypass authentication by setting the X-F [truncated]