CVE-2026-40575: OAuth2 Proxy has an Authentication Bypass via X-Forwarded-Uri Header Spoofing

Published Apr 15, 2026
·
Updated

Impact

A configuration-dependent authentication bypass exists in OAuth2 Proxy.

Deployments are affected when all of the following are true:

OAuth2 Proxy is configured with --reverse-proxy and at least one rule is defined with --skipauthroutes or the legacy --skip-auth-regex

OAuth2 Proxy may trust a client-supplied X-Forwarded-Uri header when --reverse-proxy is enabled and --skip-auth-route or --skip-auth-regex is configured. An attacker can spoof this header so OAuth2 Proxy evaluates authentication and skip-auth rules against a different path than the one actually sent to the upstream application.

This can result in an unauthenticated remote attacker bypassing authentication and accessing protected routes without a valid session.

Patches This issue is addressed as part of the newly introduced --trusted-proxy-ip flag in v7.15.2. If you leave it unset, OAuth2 Proxy will continue to trust ALL source IPs (0.0.0.0/0) for backwards compatibility, which means a client may still be able to spoof forwarded headers. Therefore after upgrading we urge you to use the new --trusted-proxy-ip flag to set the IPs or CIDR ranges of the reverse proxies that are allowed to send X-Forwarded- headers and furthermore implement the mitigation steps outlined below to properly configure your load balancer infrastructure.

Mitigation

- Strip any client-provided X-Forwarded-Uri header at the reverse proxy or load balancer level - Explicitly overwrite X-Forwarded-Uri with the actual request URI before forwarding requests to OAuth2 Proxy

Example nginx mitigation for the auth subrequest: location /internal-auth/ { internal; # Ensure external users can't access this path # Make sure the OAuth2 Proxy knows where the original request came from. proxysetheader Host $host; proxysetheader X-Real-IP $remoteaddr; # set the value to the actual $requesturi and therefore strip any user provided X-Forwarded-Uri proxysetheader X-Forwarded-Uri $requesturi; proxypass http://oauth2-proxy:4180/; } - Restrict direct client access to OAuth2 Proxy so it can only be reached through a trusted reverse proxy - Remove or narrow --skip-auth-route / --skip-auth-regex rules where possible

Other sources

OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions 7.5.0 through 7.15.1 may trust a client-supplied X-Forwarded-Uri header when --reverse-proxy is enabled and --skip-auth-regex or --skip-auth-route is configured. An attacker can spoof this header so OAuth2 Proxy evaluates authentication and skip-auth rules against a different path than the one actually sent to the upstream application. This can result in an unauthenticated remote attacker bypassing authentication and accessing protected routes without a valid session. Impacted users are deployments that run oauth2-proxy with --reverse-proxy enabled and configure at least one --skip-auth-regex or --skip-auth-route rule. This issue is patched in v7.15.2. Some workarounds are available for those who cannot upgrade immediately. Strip any client-provided X-Forwarded-Uri header at the reverse proxy or load balancer level; explicitly overwrite X-Forwarded-Uri with the actual request URI before forwarding requests to OAuth2 Proxy; restrict direct client access to OAuth2 Proxy so it can only be reached through a trusted reverse proxy; and/or remove or narrow --skip-auth-regex / --skip-auth-route rules where possible. For nginx-based deployments, ensure X-Forwarded-Uri is set by nginx and not passed through from the client.

MITRE

Affected Software

2 affected componentsFixes available
go/github.com/oauth2-proxy/oauth2-proxy/v7>=7.5.0<7.15.2
7.15.2
Oauth2 Proxy Project Oauth2 Proxy>=7.5.0<7.15.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade go/github.com/oauth2-proxy/oauth2-proxy/v7 to a version that resolves this vulnerability.

    Fixed in 7.15.2
  2. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 7.15.2
  3. Configuration

    Ensure OAuth2 Proxy is configured with `--reverse-proxy` (impacted when enabled alongside skip-auth rules).

    OAuth2 Proxy (CLI flags) --reverse-proxy = enabled
  4. Configuration

    Remove or narrow any configured `--skip-auth-route` / `--skip-auth-regex` (or legacy `--skip-auth-regex` / `--skip_auth_routes`) rules where possible, as these are required for the bypass to be exploitable.

    OAuth2 Proxy (CLI flags) --skip-auth-regex / --skip_auth_routes (legacy: --skip-auth-regex / --skip-auth-route / --skip-auth-regex) = remove or narrow
  5. Configuration

    Before forwarding requests to OAuth2 Proxy, explicitly overwrite/strip the header by setting `X-Forwarded-Uri` to the actual `$request_uri` (example: `proxy_set_header X-Forwarded-Uri $request_uri;`).

    Reverse proxy / load balancer (nginx example) proxy_set_header X-Forwarded-Uri = $request_uri
  6. Configuration

    In the reverse proxy configuration for the OAuth2 Proxy upstream, set `X-Real-IP` to `$remote_addr` (example: `proxy_set_header X-Real-IP $remote_addr;`).

    Reverse proxy / load balancer (nginx example) proxy_set_header X-Real-IP = $remote_addr
  7. Compensating control

    Restrict direct client access to OAuth2 Proxy so it can only be reached through a trusted reverse proxy (so only trusted intermediaries can send `X-Forwarded-*` headers).

Event History

Apr 15, 2026
Advisory Published
via GitHub·07:21 PM
Data Sourced
via GitHub·07:21 PM
DescriptionSeverityWeaknessAffected Software
Apr 21, 2026
CVE Published
via MITRE·11:20 PM
Data Sourced
via MITRE·11:20 PM
DescriptionSeverityWeakness
Apr 22, 2026
Data Sourced
via Red Hat·12:02 AM
DescriptionSeverityAffected Software
Data Sourced
via NVD·12:16 AM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-40575?

CVE-2026-40575 is classified as a medium severity vulnerability due to its potential for authentication bypass.

2

What causes CVE-2026-40575?

CVE-2026-40575 is caused by a configuration-dependent authentication bypass in OAuth2 Proxy when specific settings are applied.

3

How do I fix CVE-2026-40575?

To fix CVE-2026-40575, ensure that OAuth2 Proxy is not configured with the '--reverse-proxy' option along with any 'skip_auth_routes' rules.

4

Which versions of OAuth2 Proxy are affected by CVE-2026-40575?

CVE-2026-40575 affects OAuth2 Proxy versions between 7.5.0 and 7.15.2, inclusive.

5

Is there a workaround for CVE-2026-40575?

A potential workaround for CVE-2026-40575 is to avoid using the '--reverse-proxy' configuration in your OAuth2 Proxy setup.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203