Report inconsistent skip-auth path interpretation
Received public reporter credit for identifying authentication-bypass risk when OAuth2 Proxy and downstream components interpret exempted request paths differently.
oauth2-proxy/oauth2-proxy · GHSA-63jm-59jj-478j
Security research
Publicly credited as a reporter on a critical OAuth2 Proxy authentication-bypass advisory affecting ambiguous request paths and path-based authentication exemptions.
Problem
With skip-auth route or regular-expression exemptions configured, crafted dot segments, leading double slashes, or servlet matrix parameters could match a public exemption in OAuth2 Proxy but resolve downstream to a protected resource. Impact depended on the exemption and downstream routing behavior rather than affecting every deployment.
Approach
OAuth2 Proxy v7.15.5 parses authorization paths using HTTP request-target semantics and declines path exemptions for invalid or ambiguous forms before evaluating positive or negated rules. The patch leaves ordinary authenticated routing and the forwarded-header trust boundary unchanged.
Impact and scope
- Documents a remotely exploitable authentication-boundary mismatch with high confidentiality and integrity impact.
- Covers three distinct path-interpretation classes across direct-proxy and external-auth integrations.
- Provides concrete upgrade guidance, compatibility warnings, and bounded workarounds for affected operators.
- GitHub lists Goutam Adwant among five public reporters; this record claims reporting credit, not sole discovery or authorship of the patch.
Validation
- GitHub published the advisory on October 1, 2026 with critical severity and a CVSS 3.1 score of 9.1.
- The public credit list includes the goutamadwant account with reporter attribution.
- The official v7.15.5 release notes list GHSA-63jm-59jj-478j as a critical fix and document the stricter skip-auth path behavior; deployments without path-based authentication exemptions are not affected.