[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2026-76835":6},{"stargazers_count":4,"fetched_at":5},7,"2026-08-24T16:49:05.592Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":468,"aliases":469,"duplicate_of":9,"upstream":470,"downstream":471,"duplicates":472,"related":473,"reserved_at":9,"published_at":474,"modified_at":474,"state":475,"summary":476,"references_raw":483,"kevs":510,"epss":9,"epss_history":511,"metrics":512,"affected":525},"CVE-2026-76835","OAuth2 Proxy honours a client-supplied X-Forwarded-Uri header when deciding whether a request may skip authentication, because the guard added for CVE-2026-40575 is inert in the default reverse-proxy configuration. GetRequestURI in pkg/requests/util/util.go prefers that header over the real request URI whenever CanTrustForwardedHeaders returns true, and isAllowedPath in oauthproxy.go matches the skip_auth_routes and skip_auth_regex allow list against the resulting path. CanTrustForwardedHeaders in pkg/apis/middleware/scope.go grants that trust when the caller's address is in the trusted proxy set, and buildTrustedProxyNetSet falls back to defaultTrustedProxyIPs, which is 0.0.0.0/0 and ::/0, whenever reverse proxy mode is enabled without trusted_proxy_ip configured. Every client is therefore treated as a trusted proxy. An unauthenticated attacker can request a protected upstream path while setting X-Forwarded-Uri to a value matching an allow-listed route, so the skip-auth decision is made against the spoofed value while the upstream receives the protected path unchanged.",null,[11],{"_key":12,"id":12,"name":13,"description":14,"type":15,"status":16,"abstraction":17,"likelihood_of_exploit":9,"capec":18},"CWE-290","Authentication Bypass by Spoofing","This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.","weakness","Incomplete","Base",[19,194,198,202,206,282,286,290,429,433],{"id":20,"name":21,"techniques":22},"CAPEC-21","Exploitation of Trusted Identifiers",[23,140,170],{"id":24,"name":25,"tactics":26,"countermeasures":36},"T1134","Access Token Manipulation",[27,30,33],{"id":28,"name":29},"TA0030","Defense Evasion",{"id":31,"name":32},"TA0005","Stealth",{"id":34,"name":35},"TA0111","Privilege Escalation",[37,42,47,51,55,60,64,68,73,78,83,87,91,95,99,103,108,112,116,120,124,128,132,136],{"id":38,"name":39,"tactic":40},"D3-CTS","Credential Transmission Scoping",{"name":41},"Isolate",{"id":43,"name":44,"tactic":45},"D3-CCSA","Credential Compromise Scope Analysis",{"name":46},"Detect",{"id":48,"name":49,"tactic":50},"D3-OPM","Operational Process Monitoring",{"name":46},{"id":52,"name":53,"tactic":54},"D3-PSA","Process Spawn Analysis",{"name":46},{"id":56,"name":57,"tactic":58},"D3-ST","Session Termination",{"name":59},"Evict",{"id":61,"name":62,"tactic":63},"D3-CR","Credential Revocation",{"name":59},{"id":65,"name":66,"tactic":67},"D3-ANCI","Authentication Cache Invalidation",{"name":59},{"id":69,"name":70,"tactic":71},"D3-CI","Configuration Inventory",{"name":72},"Model",{"id":74,"name":75,"tactic":76},"D3-DUC","Decoy User Credential",{"name":77},"Deceive",{"id":79,"name":80,"tactic":81},"D3-CH","Credential Hardening",{"name":82},"Harden",{"id":84,"name":85,"tactic":86},"D3-HBPI","Hardware-based Process Isolation",{"name":41},{"id":88,"name":89,"tactic":90},"D3-MFA","Multi-factor Authentication",{"name":82},{"id":92,"name":93,"tactic":94},"D3-CRO","Credential Rotation",{"name":82},{"id":96,"name":97,"tactic":98},"D3-TB","Token Binding",{"name":82},{"id":100,"name":101,"tactic":102},"D3-TBA","Token-based Authentication",{"name":82},{"id":104,"name":105,"tactic":106},"D3-RC","Restore Configuration",{"name":107},"Restore",{"id":109,"name":110,"tactic":111},"D3-RIC","Reissue Credential",{"name":107},{"id":113,"name":114,"tactic":115},"D3-NTPM","Network Traffic Policy Mapping",{"name":72},{"id":117,"name":118,"tactic":119},"D3-AM","Access Modeling",{"name":72},{"id":121,"name":122,"tactic":123},"D3-SCF","System Call Filtering",{"name":41},{"id":125,"name":126,"tactic":127},"D3-AEM","Application Exception Monitoring",{"name":46},{"id":129,"name":130,"tactic":131},"D3-SCA","System Call Analysis",{"name":46},{"id":133,"name":134,"tactic":135},"D3-EAL","Executable Allowlisting",{"name":41},{"id":137,"name":138,"tactic":139},"D3-EDL","Executable Denylisting",{"name":41},{"id":141,"name":142,"tactics":143,"countermeasures":147},"T1528","Steal Application Access Token",[144],{"id":145,"name":146},"TA0031","Credential Access",[148,150,152,154,156,158,160,162,164,166,168],{"id":92,"name":93,"tactic":149},{"name":82},{"id":79,"name":80,"tactic":151},{"name":82},{"id":43,"name":44,"tactic":153},{"name":46},{"id":96,"name":97,"tactic":155},{"name":82},{"id":74,"name":75,"tactic":157},{"name":77},{"id":100,"name":101,"tactic":159},{"name":82},{"id":88,"name":89,"tactic":161},{"name":82},{"id":61,"name":62,"tactic":163},{"name":59},{"id":109,"name":110,"tactic":165},{"name":107},{"id":38,"name":39,"tactic":167},{"name":41},{"id":65,"name":66,"tactic":169},{"name":59},{"id":171,"name":172,"tactics":173,"countermeasures":175},"T1539","Steal Web Session Cookie",[174],{"id":145,"name":146},[176,178,180,182,184,186,188,190,192],{"id":43,"name":44,"tactic":177},{"name":46},{"id":109,"name":110,"tactic":179},{"name":107},{"id":92,"name":93,"tactic":181},{"name":82},{"id":65,"name":66,"tactic":183},{"name":59},{"id":61,"name":62,"tactic":185},{"name":59},{"id":74,"name":75,"tactic":187},{"name":77},{"id":38,"name":39,"tactic":189},{"name":41},{"id":79,"name":80,"tactic":191},{"name":82},{"id":88,"name":89,"tactic":193},{"name":82},{"id":195,"name":196,"techniques":197},"CAPEC-22","Exploiting Trust in Client",[],{"id":199,"name":200,"techniques":201},"CAPEC-459","Creating a Rogue Certification Authority Certificate",[],{"id":203,"name":204,"techniques":205},"CAPEC-461","Web Services API Signature Forgery Leveraging Hash Function Extension Weakness",[],{"id":207,"name":208,"techniques":209},"CAPEC-473","Signature Spoof",[210,273],{"id":211,"name":212,"tactics":213,"countermeasures":216},"T1036.001","Invalid Code Signature",[214,215],{"id":28,"name":29},{"id":31,"name":32},[217,219,223,227,231,235,237,241,245,249,253,257,261,265,269],{"id":137,"name":138,"tactic":218},{"name":41},{"id":220,"name":221,"tactic":222},"D3-DA","Dynamic Analysis",{"name":46},{"id":224,"name":225,"tactic":226},"D3-FEV","File Eviction",{"name":59},{"id":228,"name":229,"tactic":230},"D3-DF","Decoy File",{"name":77},{"id":232,"name":233,"tactic":234},"D3-CF","Content Filtering",{"name":41},{"id":133,"name":134,"tactic":236},{"name":41},{"id":238,"name":239,"tactic":240},"D3-FA","File Analysis",{"name":46},{"id":242,"name":243,"tactic":244},"D3-LFP","Local File Permissions",{"name":41},{"id":246,"name":247,"tactic":248},"D3-CM","Content Modification",{"name":41},{"id":250,"name":251,"tactic":252},"D3-RF","Restore File",{"name":107},{"id":254,"name":255,"tactic":256},"D3-EFA","Emulated File Analysis",{"name":46},{"id":258,"name":259,"tactic":260},"D3-CQ","Content Quarantine",{"name":41},{"id":262,"name":263,"tactic":264},"D3-RFAM","Remote File Access Mediation",{"name":41},{"id":266,"name":267,"tactic":268},"D3-FE","File Encryption",{"name":82},{"id":270,"name":271,"tactic":272},"D3-FIM","File Integrity Monitoring",{"name":46},{"id":274,"name":275,"tactics":276,"countermeasures":281},"T1553.002","Code Signing",[277,278],{"id":28,"name":29},{"id":279,"name":280},"TA0112","Defense Impairment",[],{"id":283,"name":284,"techniques":285},"CAPEC-476","Signature Spoofing by Misrepresentation",[],{"id":287,"name":288,"techniques":289},"CAPEC-59","Session Credential Falsification through Prediction",[],{"id":291,"name":292,"techniques":293},"CAPEC-60","Reusing Session IDs (aka Session Replay)",[294,324],{"id":295,"name":296,"tactics":297,"countermeasures":301},"T1134.001","Token Impersonation/Theft",[298,299,300],{"id":28,"name":29},{"id":31,"name":32},{"id":34,"name":35},[302,304,306,308,310,312,314,316,318,320,322],{"id":88,"name":89,"tactic":303},{"name":82},{"id":74,"name":75,"tactic":305},{"name":77},{"id":109,"name":110,"tactic":307},{"name":107},{"id":38,"name":39,"tactic":309},{"name":41},{"id":96,"name":97,"tactic":311},{"name":82},{"id":61,"name":62,"tactic":313},{"name":59},{"id":65,"name":66,"tactic":315},{"name":59},{"id":79,"name":80,"tactic":317},{"name":82},{"id":100,"name":101,"tactic":319},{"name":82},{"id":92,"name":93,"tactic":321},{"name":82},{"id":43,"name":44,"tactic":323},{"name":46},{"id":325,"name":326,"tactics":327,"countermeasures":332},"T1550.004","Web Session Cookie",[328,329],{"id":28,"name":29},{"id":330,"name":331},"TA0109","Lateral Movement",[333,335,339,341,345,349,353,357,361,363,367,369,373,377,379,383,387,391,395,397,401,405,407,411,413,417,419,421,423,425],{"id":84,"name":85,"tactic":334},{"name":41},{"id":336,"name":337,"tactic":338},"D3-PLA","Process Lineage Analysis",{"name":46},{"id":61,"name":62,"tactic":340},{"name":59},{"id":342,"name":343,"tactic":344},"D3-CSPP","Client-server Payload Profiling",{"name":46},{"id":346,"name":347,"tactic":348},"D3-HR","Host Reboot",{"name":59},{"id":350,"name":351,"tactic":352},"D3-NTSA","Network Traffic Signature Analysis",{"name":46},{"id":354,"name":355,"tactic":356},"D3-UGLPA","User Geolocation Logon Pattern Analysis",{"name":46},{"id":358,"name":359,"tactic":360},"D3-APCA","Application Protocol Command Analysis",{"name":46},{"id":43,"name":44,"tactic":362},{"name":46},{"id":364,"name":365,"tactic":366},"D3-NTCD","Network Traffic Community Deviation",{"name":46},{"id":92,"name":93,"tactic":368},{"name":82},{"id":370,"name":371,"tactic":372},"D3-PS","Process Suspension",{"name":59},{"id":374,"name":375,"tactic":376},"D3-KBPI","Kernel-based Process Isolation",{"name":41},{"id":121,"name":122,"tactic":378},{"name":41},{"id":380,"name":381,"tactic":382},"D3-PT","Process Termination",{"name":59},{"id":384,"name":385,"tactic":386},"D3-HS","Host Shutdown",{"name":59},{"id":388,"name":389,"tactic":390},"D3-PHDURA","Per Host Download-Upload Ratio Analysis",{"name":46},{"id":392,"name":393,"tactic":394},"D3-PSMD","Process Self-Modification Detection",{"name":46},{"id":74,"name":75,"tactic":396},{"name":77},{"id":398,"name":399,"tactic":400},"D3-WSAM","Web Session Access Mediation",{"name":41},{"id":402,"name":403,"tactic":404},"D3-PMAD","Protocol Metadata Anomaly Detection",{"name":46},{"id":79,"name":80,"tactic":406},{"name":82},{"id":408,"name":409,"tactic":410},"D3-ABPI","Application-based Process Isolation",{"name":41},{"id":109,"name":110,"tactic":412},{"name":107},{"id":414,"name":415,"tactic":416},"D3-RTSD","Remote Terminal Session Detection",{"name":46},{"id":38,"name":39,"tactic":418},{"name":41},{"id":65,"name":66,"tactic":420},{"name":59},{"id":88,"name":89,"tactic":422},{"name":82},{"id":52,"name":53,"tactic":424},{"name":46},{"id":426,"name":427,"tactic":428},"D3-NTF","Network Traffic Filtering",{"name":41},{"id":430,"name":431,"techniques":432},"CAPEC-667","Bluetooth Impersonation AttackS (BIAS)",[],{"id":434,"name":435,"techniques":436},"CAPEC-94","Adversary in the Middle (AiTM)",[437],{"id":438,"name":439,"tactics":440,"countermeasures":445},"T1557","Adversary-in-the-Middle",[441,442],{"id":145,"name":146},{"id":443,"name":444},"TA0100","Collection",[446,448,450,452,454,456,458,460,462,464],{"id":426,"name":427,"tactic":447},{"name":41},{"id":354,"name":355,"tactic":449},{"name":46},{"id":402,"name":403,"tactic":451},{"name":46},{"id":342,"name":343,"tactic":453},{"name":46},{"id":388,"name":389,"tactic":455},{"name":46},{"id":350,"name":351,"tactic":457},{"name":46},{"id":358,"name":359,"tactic":459},{"name":46},{"id":364,"name":365,"tactic":461},{"name":46},{"id":414,"name":415,"tactic":463},{"name":46},{"id":465,"name":466,"tactic":467},"D3-CAA","Connection Attempt Analysis",{"name":46},[],[],[],[],[],[],"2026-08-24T17:55:39.829Z","Received",{"cisa_kev":477,"cisa_ransomware":477,"cisa_vendor":9,"epss_severity":9,"epss_score":9,"severity":478,"severity_score":479,"severity_version":480,"severity_source":481,"severity_vector":482,"severity_status":475},false,"critical",9.3,"v4.0","cve.org","CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N",[484,490,495,500,505],{"url":485,"sources":486,"tags":488},"https://github.com/oauth2-proxy/oauth2-proxy",[481,487],"nvd",[489],"Product",{"url":491,"sources":492,"tags":493},"https://github.com/oauth2-proxy/oauth2-proxy/issues/3506",[481,487],[494],"Issue Tracking",{"url":496,"sources":497,"tags":498},"https://github.com/oauth2-proxy/oauth2-proxy/blob/v7.15.4/pkg/apis/middleware/scope.go",[481,487],[499],"Technical Description",{"url":501,"sources":502,"tags":503},"https://github.com/oauth2-proxy/oauth2-proxy/security/advisories/GHSA-7x63-xv5r-3p2x",[481,487],[504],"Vendor Advisory",{"url":506,"sources":507,"tags":508},"https://www.vulncheck.com/advisories/oauth2-proxy-through-authentication-bypass-via-x-forwarded-uri-under-the-default-trusted-proxy-set",[481,487],[509],"Third Party Advisory",[],[],[513,521],{"source":481,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":514,"cvss_v4_0":520},{"baseScore":515,"baseSeverity":516,"vectorString":517,"impactScore":518,"exploitabilityScore":519},9.1,"CRITICAL","CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",8.7,10,{"baseScore":479,"baseSeverity":516,"vectorString":482,"impactScore":9,"exploitabilityScore":9},{"source":487,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":522,"cvss_v4_0":523},{"baseScore":515,"baseSeverity":516,"vectorString":517,"impactScore":518,"exploitabilityScore":519},{"baseScore":479,"baseSeverity":516,"vectorString":524,"impactScore":9,"exploitabilityScore":9},"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",[526],{"ecosystem":9,"name":527,"vendor":527,"product":527,"cpe_part":528,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":529},"oauth2-proxy","a",[530],{"version":531,"is_range":532,"range_type":481,"version_start":533,"version_start_type":534,"version_end":535,"version_end_type":534,"fixed_in":9},">= 7.15.2, \u003C= 7.15.4",true,"7.15.2","including","7.15.4"]