Red HatCVE-2026-49332
A flaw was found in openshift/oauth-proxy
High8.5CVE-2026-49332 · Published Jul 28, 2026 · updated Sep 21, 2026
A flaw was found in openshift/oauth-proxy. The proxy sets authenticated identity headers using only dash-variant keys (X-Forwarded-User) but does not strip underscore-variant keys (X_Forwarded_User) from incoming requests. WSGI and PHP frameworks normalize both variants to the same variable, allowing an authenticated low-privilege user to smuggle a forged identity that may override the legitimate authenticated identity in the upstream application.
Affected versions
The source does not list versions here. See the source advisory for affected products and fixes.
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-436
- www.cve.org/CVERecord?id=CVE-2026-49332
- nvd.nist.gov/vuln/detail/CVE-2026-49332
- access.redhat.com/errata/RHSA-2026:50681
- access.redhat.com/errata/RHSA-2026:50758
- access.redhat.com/errata/RHSA-2026:51007
- access.redhat.com/errata/RHSA-2026:51013
- access.redhat.com/errata/RHSA-2026:51022
- access.redhat.com/errata/RHSA-2026:51025
- access.redhat.com/errata/RHSA-2026:51038
- access.redhat.com/errata/RHSA-2026:54188
- access.redhat.com/errata/RHSA-2026:54206
- access.redhat.com/errata/RHSA-2026:56912
- access.redhat.com/errata/RHSA-2026:60023
- access.redhat.com/security/cve/CVE-2026-49332
- bugzilla.redhat.com/show_bug.cgi?id=2483253
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 28 | Red Hat CRIU: code injection | High7.8 | No fix yet |
| Jul 28 | Red Hat sg3_utils. The sg_inq command: code execution | High7.6 | No fix yet |
| Jul 28 | Red Hat Dogtag PKI: denial of service | Medium6.5 | No fix yet |
| Jul 28 | Red Hat GStreamer: out-of-bounds read | Low3.3 | No fix yet |
| Jul 27 | Red Hat file-sgi plugin: integer overflow | Medium5.5 | No fix yet |
| Jul 27 | Red Hat file-fits plugin: integer overflow | High7.8 | No fix yet |