CVE-2026-40575: OAuth2 Proxy has an Authentication Bypass via X-Forwarded-Uri Header Spoofing
Impact
A configuration-dependent authentication bypass exists in OAuth2 Proxy.
Deployments are affected when all of the following are true:
OAuth2 Proxy is configured with --reverse-proxy and at least one rule is defined with --skipauthroutes or the legacy --skip-auth-regex
OAuth2 Proxy may trust a client-supplied X-Forwarded-Uri header when --reverse-proxy is enabled and --skip-auth-route or --skip-auth-regex is configured. An attacker can spoof this header so OAuth2 Proxy evaluates authentication and skip-auth rules against a different path than the one actually sent to the upstream application.
This can result in an unauthenticated remote attacker bypassing authentication and accessing protected routes without a valid session.
Patches This issue is addressed as part of the newly introduced --trusted-proxy-ip flag in v7.15.2. If you leave it unset, OAuth2 Proxy will continue to trust ALL source IPs (0.0.0.0/0) for backwards compatibility, which means a client may still be able to spoof forwarded headers. Therefore after upgrading we urge you to use the new --trusted-proxy-ip flag to set the IPs or CIDR ranges of the reverse proxies that are allowed to send X-Forwarded- headers and furthermore implement the mitigation steps outlined below to properly configure your load balancer infrastructure.
Mitigation
- Strip any client-provided X-Forwarded-Uri header at the reverse proxy or load balancer level - Explicitly overwrite X-Forwarded-Uri with the actual request URI before forwarding requests to OAuth2 Proxy
Example nginx mitigation for the auth subrequest: location /internal-auth/ { internal; # Ensure external users can't access this path # Make sure the OAuth2 Proxy knows where the original request came from. proxysetheader Host $host; proxysetheader X-Real-IP $remoteaddr; # set the value to the actual $requesturi and therefore strip any user provided X-Forwarded-Uri proxysetheader X-Forwarded-Uri $requesturi; proxypass http://oauth2-proxy:4180/; } - Restrict direct client access to OAuth2 Proxy so it can only be reached through a trusted reverse proxy - Remove or narrow --skip-auth-route / --skip-auth-regex rules where possible
Other sources
OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions 7.5.0 through 7.15.1 may trust a client-supplied X-Forwarded-Uri header when --reverse-proxy is enabled and --skip-auth-regex or --skip-auth-route is configured. An attacker can spoof this header so OAuth2 Proxy evaluates authentication and skip-auth rules against a different path than the one actually sent to the upstream application. This can result in an unauthenticated remote attacker bypassing authentication and accessing protected routes without a valid session. Impacted users are deployments that run oauth2-proxy with --reverse-proxy enabled and configure at least one --skip-auth-regex or --skip-auth-route rule. This issue is patched in v7.15.2. Some workarounds are available for those who cannot upgrade immediately. Strip any client-provided X-Forwarded-Uri header at the reverse proxy or load balancer level; explicitly overwrite X-Forwarded-Uri with the actual request URI before forwarding requests to OAuth2 Proxy; restrict direct client access to OAuth2 Proxy so it can only be reached through a trusted reverse proxy; and/or remove or narrow --skip-auth-regex / --skip-auth-route rules where possible. For nginx-based deployments, ensure X-Forwarded-Uri is set by nginx and not passed through from the client.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
go/github.com/oauth2-proxy/oauth2-proxy/v7to a version that resolves this vulnerability.Fixed in 7.15.2 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 7.15.2 - Configuration
Ensure OAuth2 Proxy is configured with `--reverse-proxy` (impacted when enabled alongside skip-auth rules).
OAuth2 Proxy (CLI flags) --reverse-proxy = enabled - Configuration
Remove or narrow any configured `--skip-auth-route` / `--skip-auth-regex` (or legacy `--skip-auth-regex` / `--skip_auth_routes`) rules where possible, as these are required for the bypass to be exploitable.
OAuth2 Proxy (CLI flags) --skip-auth-regex / --skip_auth_routes (legacy: --skip-auth-regex / --skip-auth-route / --skip-auth-regex) = remove or narrow - Configuration
Before forwarding requests to OAuth2 Proxy, explicitly overwrite/strip the header by setting `X-Forwarded-Uri` to the actual `$request_uri` (example: `proxy_set_header X-Forwarded-Uri $request_uri;`).
Reverse proxy / load balancer (nginx example) proxy_set_header X-Forwarded-Uri = $request_uri - Configuration
In the reverse proxy configuration for the OAuth2 Proxy upstream, set `X-Real-IP` to `$remote_addr` (example: `proxy_set_header X-Real-IP $remote_addr;`).
Reverse proxy / load balancer (nginx example) proxy_set_header X-Real-IP = $remote_addr - Compensating control
Restrict direct client access to OAuth2 Proxy so it can only be reached through a trusted reverse proxy (so only trusted intermediaries can send `X-Forwarded-*` headers).
Event History
Frequently Asked Questions
What is the severity of CVE-2026-40575?
CVE-2026-40575 is classified as a medium severity vulnerability due to its potential for authentication bypass.
What causes CVE-2026-40575?
CVE-2026-40575 is caused by a configuration-dependent authentication bypass in OAuth2 Proxy when specific settings are applied.
How do I fix CVE-2026-40575?
To fix CVE-2026-40575, ensure that OAuth2 Proxy is not configured with the '--reverse-proxy' option along with any 'skip_auth_routes' rules.
Which versions of OAuth2 Proxy are affected by CVE-2026-40575?
CVE-2026-40575 affects OAuth2 Proxy versions between 7.5.0 and 7.15.2, inclusive.
Is there a workaround for CVE-2026-40575?
A potential workaround for CVE-2026-40575 is to avoid using the '--reverse-proxy' configuration in your OAuth2 Proxy setup.