Skip to content
Red HatCVE-2026-49332

A flaw was found in openshift/oauth-proxy

High8.5CVE-2026-49332 · Published Jul 28, 2026 · updated Sep 21, 2026

A flaw was found in openshift/oauth-proxy. The proxy sets authenticated identity headers using only dash-variant keys (X-Forwarded-User) but does not strip underscore-variant keys (X_Forwarded_User) from incoming requests. WSGI and PHP frameworks normalize both variants to the same variable, allowing an authenticated low-privilege user to smuggle a forged identity that may override the legitimate authenticated identity in the upstream application.

Red Hat advisory

Affected versions

The source does not list versions here. See the source advisory for affected products and fixes.
Details and references

More Red Hat advisories

All Red Hat
Advisory
Red Hat CRIU: code injection
High7.8Jul 28
Red Hat sg3_utils. The sg_inq command: code execution
High7.6Jul 28
Red Hat Dogtag PKI: denial of service
Medium6.5Jul 28
Red Hat GStreamer: out-of-bounds read
Low3.3Jul 28
Red Hat file-sgi plugin: integer overflow
Medium5.5Jul 27
Red Hat file-fits plugin: integer overflow
High7.8Jul 27

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.