Back

MEDIUM

Openshift/oauth-proxy: openshift/oauth-proxy: unauthenticated identity header injection on whitelisted paths

Published Aug 5, 2026

Description

A flaw was found in openshift/oauth-proxy. On paths configured to bypass authentication (skip-auth-regex), the proxy forwards client-supplied identity headers (X-Forwarded-User, X-Forwarded-Email, X-Forwarded-Access-Token) to the upstream application without stripping them. An unauthenticated attacker can inject forged identity headers on whitelisted paths.

Affected products

Remediation

Vendor solution

Review and minimize skip-auth-regex configurations. Add middleware in upstream applications to ignore X-Forwarded-User on unauthenticated paths.

Red Hat mitigation

Review and minimize skip-auth-regex configurations. Add middleware in upstream applications to ignore X-Forwarded-User on unauthenticated paths.

Metrics

Weaknesses (1)

References (4)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Aug 5, 2026
Updated Aug 6, 2026
Reserved May 29, 2026
CISA Vulnrichment
Updated Aug 6, 2026
NVD
Status Awaiting Analysis
Modified Aug 6, 2026
Red Hat
Severity Moderate
Public date Aug 5, 2026