Warning: Critical authentication bypass vulnerability in OAuth2- Proxy can lead to attackers gaining unauthorised access to protected resources. Patch Immediately!
ID: bb010742-a48b-5d71-874d-22ad7da889d9
STIX ID: report--bb010742-a48b-5d71-874d-22ad7da889d9
OAuth2-Proxy CVE-2025-54576 is a high-severity authentication-bypass vulnerability affecting versions prior to v7.11.0 where skip_auth_routes regexes are matched against the full request URI (path + query) instead of the path only, allowing attackers to append query parameters to access protected endpoints; CVSS 3.1 score 9.1. A patch is available (v7.11.0) and recommended mitigations include updating, auditing and anchoring regex patterns, and stripping query parameters before matching; no active exploitation was reported as of 31 July 2025.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
