OAuth2 Proxy / OAuth2 Proxy
Published security creditSecurityPublished Oct 1, 2026

Report inconsistent skip-auth path interpretation

Received public reporter credit for identifying authentication-bypass risk when OAuth2 Proxy and downstream components interpret exempted request paths differently.

oauth2-proxy/oauth2-proxy · GHSA-63jm-59jj-478j

Security research

Publicly credited as a reporter on a critical OAuth2 Proxy authentication-bypass advisory affecting ambiguous request paths and path-based authentication exemptions.

Problem

With skip-auth route or regular-expression exemptions configured, crafted dot segments, leading double slashes, or servlet matrix parameters could match a public exemption in OAuth2 Proxy but resolve downstream to a protected resource. Impact depended on the exemption and downstream routing behavior rather than affecting every deployment.

Approach

OAuth2 Proxy v7.15.5 parses authorization paths using HTTP request-target semantics and declines path exemptions for invalid or ambiguous forms before evaluating positive or negated rules. The patch leaves ordinary authenticated routing and the forwarded-header trust boundary unchanged.

Impact and scope

  • Documents a remotely exploitable authentication-boundary mismatch with high confidentiality and integrity impact.
  • Covers three distinct path-interpretation classes across direct-proxy and external-auth integrations.
  • Provides concrete upgrade guidance, compatibility warnings, and bounded workarounds for affected operators.
  • GitHub lists Goutam Adwant among five public reporters; this record claims reporting credit, not sole discovery or authorship of the patch.

Validation

  • GitHub published the advisory on October 1, 2026 with critical severity and a CVSS 3.1 score of 9.1.
  • The public credit list includes the goutamadwant account with reporter attribution.
  • The official v7.15.5 release notes list GHSA-63jm-59jj-478j as a critical fix and document the stricter skip-auth path behavior; deployments without path-based authentication exemptions are not affected.