OAuth2 Proxy Authentication Bypass: Early Warning
OAuth2 Proxy reportedly has an authentication bypass vulnerability that allows unauthenticated remote attackers to access protected routes. Users of oauth2_proxy (go) versions up to and including v7.15.1 are potentially affected.
What happened
OAuth2 Proxy is under investigation for an authentication bypass vulnerability tracked as GHSA-7X63-XV5R-3P2X. This vulnerability appears to allow attackers to spoof the X-Forwarded-Uri header, potentially bypassing authentication and accessing protected routes without a valid session. The specific CVE identifier and detailed technical information are not yet confirmed. To mitigate potential risk, it is recommended to upgrade to oauth2_proxy v7.15.2 and configure the --trusted-proxy-ip flag. For more detailed information, consult the primary sources.
How 0Day mitigates this
oauth2_proxy is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.