Two high-severity vulnerabilities in OAuth2 Proxy can let unauthenticated remote attackers reach protected upstream resources in specific reverse-proxy deployments. CVE-2026-34457 affects versions prior to 7.15.2 when OAuth2 Proxy is used with auth_request-style integrations such as nginx auth_request and either --ping-user-agent or --gcp-healthchecks is enabled. In that configuration, any request carrying the configured health-check User-Agent can be treated as a successful health check regardless of the requested path, creating an authentication bypass. The flaw is tracked as CWE-290 and carries a CVSS 3.1 score vector of AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N.
A second flaw, CVE-2026-40575, affects OAuth2 Proxy versions 7.5.0 through 7.15.1 when --reverse-proxy is enabled alongside --skip-auth-regex or --skip-auth-route. In those setups, the product may trust a client-supplied X-Forwarded-Uri header, allowing attackers to spoof the header so authentication and skip-auth rules are evaluated against a different path than the one actually forwarded upstream. Both issues were fixed in OAuth2 Proxy 7.15.2. Recommended mitigations include upgrading immediately, stripping or overwriting X-Forwarded-Uri, restricting direct access to OAuth2 Proxy, and narrowing or removing skip-auth rules where possible.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
OAuth2 Proxy version 7.15.2 fixed CVE-2026-41059, a configuration-dependent authentication bypass affecting versions 7.5.0 through 7.15.1 when skip_auth_routes or legacy skip_auth_regex used overly broad patterns. Attackers could craft paths containing # or %23 so public allowlist checks matched while backend applications served protected content.
OAuth2 Proxy version 7.15.2 also patched CVE-2026-40575, which could let unauthenticated remote attackers bypass authentication in specific reverse-proxy configurations. Recommended mitigations included stripping or overwriting X-Forwarded-Uri, restricting direct access to OAuth2 Proxy, and tightening skip-auth rules.
GitHub Security Advisories received CVE-2026-40575 on April 22, 2026, describing an authentication bypass in OAuth2 Proxy versions 7.5.0 through 7.15.1 when reverse-proxy mode and skip-auth rules are enabled. The flaw allows attackers to spoof the X-Forwarded-Uri header so authentication is evaluated against a different path than the one forwarded upstream.
OAuth2 Proxy released version 7.15.2 to fix CVE-2026-34457, a configuration-dependent authentication bypass affecting auth_request-style deployments that enabled ping-user-agent or GCP health checks. In vulnerable setups, attackers could send the configured health-check User-Agent to access protected upstream resources without authentication.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.