logo

Critical 9.1 Bypass in OAuth2 Proxy Exposes Upstream Resources

ID: 84c7ad0a-2bc7-5b32-81d1-e052bcb19289

STIX ID: report--84c7ad0a-2bc7-5b32-81d1-e052bcb19289

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-04-16

Date Updated: 2026-04-23

Author: Ddos

...
...

**Executive summary:** A critical OAuth2 Proxy vulnerability (CVE-2026-34457, CVSS 9.1) can allow unauthenticated attackers to bypass authentication by spoofing health-check User-Agent strings when the proxy is used in auth_request mode with --ping-user-agent or --gcp-healthchecks enabled; affected deployments should upgrade to v7.15.2 or apply mitigations (disable the flags, sanitize User-Agent headers at the reverse proxy, or use isolated path-based health checks).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.