logo

Warning: Critical authentication bypass vulnerability in OAuth2- Proxy can lead to attackers gaining unauthorised access to protected resources. Patch Immediately!

ID: bb010742-a48b-5d71-874d-22ad7da889d9

STIX ID: report--bb010742-a48b-5d71-874d-22ad7da889d9

Feed Name: Centre for Cybersecurity Belgium Advisories Feed

Threat Score
80/100

Date Published: 2025-07-31

Date Updated: 2026-07-24

...
...

OAuth2-Proxy CVE-2025-54576 is a high-severity authentication-bypass vulnerability affecting versions prior to v7.11.0 where skip_auth_routes regexes are matched against the full request URI (path + query) instead of the path only, allowing attackers to append query parameters to access protected endpoints; CVSS 3.1 score 9.1. A patch is available (v7.11.0) and recommended mitigations include updating, auditing and anchoring regex patterns, and stripping query parameters before matching; no active exploitation was reported as of 31 July 2025.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.