CVE-2025-64484 affects OAuth2-Proxy versions prior to 7.13.0 when deployed in front of applications or frameworks that normalize underscores to dashes in HTTP header names. OAuth2-Proxy strips standard hyphenated X-Forwarded-* headers from client requests, but did not strip underscore variants such as X_Forwarded_Email or other X_Forwarded_* forms. In affected deployments, an authenticated attacker can supply underscore-form headers that pass through OAuth2-Proxy’s filtering logic and are then normalized by the upstream application into trusted hyphenated equivalents. This can cause the backend to accept attacker-controlled values as authentication or identity headers. OAuth2-Proxy’s own authentication and authorization are not directly bypassed; the flaw is in incomplete header sanitization before forwarding requests upstream.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a proof-of-concept (PoC) exploit for CVE-2025-64484, a header smuggling vulnerability in OAuth2-Proxy versions prior to 7.13.0. The exploit targets deployments where OAuth2-Proxy is used in front of a WSGI backend (such as Flask or Django) that normalizes HTTP headers with underscores and dashes. The main exploit file, 'CVE-2025-64484.py', is a Python script that sends a crafted HTTP GET request to the target OAuth2-Proxy endpoint, injecting a spoofed 'X_Auth_Request_User' header using an underscore instead of a dash. If the backend normalizes this header and trusts it for authentication, the attacker can impersonate arbitrary users, leading to privilege escalation or identity spoofing. The script also attempts to detect the OAuth2-Proxy version by inspecting the 'Server' header. The README.md provides detailed background, usage instructions, and mitigation advice. No hardcoded IPs or domains are present; the script is designed to be run against user-specified targets. The exploit is educational and intended for testing environments only.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.