When Proxies Become Attack Vectors Through Header Injection
ID: 4d56ed2e-4b0d-5f39-a9f4-5245784c4574
STIX ID: report--4d56ed2e-4b0d-5f39-a9f4-5245784c4574
Feed Name: Security Boulevard
Threat Score
CVE-2025-64484 is a header sanitization vulnerability in OAuth2-proxy: the proxy strips hyphenated security headers but fails to filter underscore variants (e.g., X_Forwarded_Email). Backend frameworks that normalize underscores to hyphens may treat these injected headers as trusted authentication headers, enabling attacker impersonation of any user (including admins) and potential header-based injection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
