PatchSiren

oauth2-proxy CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL oauth2-proxy CVE published 2026-08-24

CVE-2026-76835

An authentication bypass vulnerability exists in OAuth2 Proxy due to improper handling of the X-Forwarded-Uri header. This allows an unauthenticated attacker to access protected upstream paths by spoofing the URI, potentially leading to unauthorized access. The vulnerability arises from OAuth2 Proxy's default configuration, which trusts all proxies. An attacker can bypass authentication by setting the X-F [truncated]