Critical 9.1 Bypass in OAuth2 Proxy Exposes Upstream Resources
ID: 84c7ad0a-2bc7-5b32-81d1-e052bcb19289
STIX ID: report--84c7ad0a-2bc7-5b32-81d1-e052bcb19289
Feed Name: securityonline.info
Threat Score
**Executive summary:** A critical OAuth2 Proxy vulnerability (CVE-2026-34457, CVSS 9.1) can allow unauthenticated attackers to bypass authentication by spoofing health-check User-Agent strings when the proxy is used in auth_request mode with --ping-user-agent or --gcp-healthchecks enabled; affected deployments should upgrade to v7.15.2 or apply mitigations (disable the flags, sanitize User-Agent headers at the reverse proxy, or use isolated path-based health checks).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
