Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-5hvv-m4w4-gf6v | OAuth2 Proxy's Health Check User-Agent Matching Bypasses Authentication in auth_request Mode |
Thu, 23 Apr 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:oauth2_proxy_project:oauth2_proxy:*:*:*:*:*:*:*:* |
Wed, 15 Apr 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 15 Apr 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Oauth2 Proxy Project
Oauth2 Proxy Project oauth2 Proxy |
|
| Vendors & Products |
Oauth2 Proxy Project
Oauth2 Proxy Project oauth2 Proxy |
Tue, 14 Apr 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions prior to 7.15.2 contain a configuration-dependent authentication bypass in deployments where OAuth2 Proxy is used with an auth_request-style integration (such as nginx auth_request) and either --ping-user-agent is set or --gcp-healthchecks is enabled. In affected configurations, OAuth2 Proxy treats any request with the configured health check User-Agent value as a successful health check regardless of the requested path, allowing an unauthenticated remote attacker to bypass authentication and access protected upstream resources. Deployments that do not use auth_request-style subrequests or that do not enable --ping-user-agent/--gcp-healthchecks are not affected. This issue is fixed in 7.15.2. | |
| Title | OAuth2 Proxy: Health Check User-Agent Matching Bypasses Authentication in auth_request Mode | |
| Weaknesses | CWE-290 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-15T17:43:30.711Z
Reserved: 2026-03-27T18:18:14.895Z
Link: CVE-2026-34457
Updated: 2026-04-15T17:43:27.058Z
Status : Analyzed
Published: 2026-04-14T23:16:28.330
Modified: 2026-04-23T14:14:48.253
Link: CVE-2026-34457
No data.
OpenCVE Enrichment
Updated: 2026-04-15T14:31:57Z
Github GHSA