OAuth2 Proxy is vulnerable to an authentication bypass when configured with `--reverse-proxy` and `--skip_auth_routes` or `--skip_auth_regex`; by spoofing the `X-Forwarded-Uri` header, an attacker can bypass authentication and access protected routes without a valid session.
OAuth2 Proxy
oauth2-proxy
authentication-bypass
reverse-proxy
header-spoofing
2r
1t
2c
updated