CVE-2026-76835 | oauth2-proxy OAuth2 Proxy up to 7.15.4 Reverse-Proxy util.go GetRequestURI X-Forwarded-Uri access control
A vulnerability labeled as critical has been found in oauth2-proxy OAuth2 Proxy up to 7.15.4. This vulnerability affects the function GetRequestURI of the file pkg/requests/util/util.go of the component Reverse-Proxy. The manipulation of the argument X-Forwarded-Uri results in improper access controls.
This vulnerability is reported as CVE-2026-76835. The attack can be launched remotely. No exploit exists.VulDB Recent EntriesRead More