A flaw was found in openshift/oauth-proxy. On paths configured to bypass authentication (skip-auth-regex), the proxy forwards client-supplied identity headers (X-Forwarded-User, X-Forwarded-Email, X-Forwarded-Access-Token) to the upstream application without stripping them. An unauthenticated attacker can inject forged identity headers on whitelisted paths.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
Review and minimize skip-auth-regex configurations. Add middleware in upstream applications to ignore X-Forwarded-User on unauthenticated paths.
References
History
Wed, 05 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in openshift/oauth-proxy. On paths configured to bypass authentication (skip-auth-regex), the proxy forwards client-supplied identity headers (X-Forwarded-User, X-Forwarded-Email, X-Forwarded-Access-Token) to the upstream application without stripping them. An unauthenticated attacker can inject forged identity headers on whitelisted paths. | |
| Title | Openshift/oauth-proxy: openshift/oauth-proxy: unauthenticated identity header injection on whitelisted paths | |
| First Time appeared |
Redhat
Redhat openshift |
|
| Weaknesses | CWE-345 | |
| CPEs | cpe:/a:redhat:openshift:4 | |
| Vendors & Products |
Redhat
Redhat openshift |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-08-05T14:40:45.147Z
Reserved: 2026-05-29T13:28:56.552Z
Link: CVE-2026-49331
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-05T16:30:13Z
Weaknesses