{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/tags/header-smuggling/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.5,"id":"CVE-2026-49332"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Red Hat OpenShift Container Platform 4 (openshift4/ose-oauth-proxy)","Red Hat OpenShift Container Platform 4 (openshift4/ose-oauth-proxy-rhel9)"],"_cs_severities":["high"],"_cs_tags":["cloud","vulnerability","privilege-escalation","header-smuggling","openshift","red-hat","cve"],"_cs_type":"advisory","_cs_vendors":["Red Hat"],"content_html":"\u003cp\u003eA significant flaw, identified as CVE-2026-49332, has been discovered in the \u003ccode\u003eopenshift/oauth-proxy\u003c/code\u003e component of Red Hat OpenShift Container Platform 4. This vulnerability enables an authenticated user with low privileges to bypass identity checks and achieve privilege escalation within upstream applications. The core issue stems from the proxy's inconsistent handling of HTTP headers; while it uses dash-variant keys (e.g., \u003ccode\u003eX-Forwarded-User\u003c/code\u003e) to set authenticated identity, it fails to strip underscore-variant keys (e.g., \u003ccode\u003eX_Forwarded_User\u003c/code\u003e) from incoming requests. This oversight allows an attacker to include a forged \u003ccode\u003eX_Forwarded_User\u003c/code\u003e header. Upstream application frameworks, such as WSGI and PHP, commonly normalize both dash and underscore variants to the same internal variable, leading to the forged identity overriding the legitimate one established by the proxy. This can result in unauthorized access or actions performed under a higher-privileged identity.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn authenticated user with low privileges crafts a malicious HTTP request targeting an upstream application protected by the \u003ccode\u003eopenshift/oauth-proxy\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe malicious request includes a forged \u003ccode\u003eX_Forwarded_User\u003c/code\u003e header containing a desired high-privilege identity (e.g., an administrator).\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003eopenshift/oauth-proxy\u003c/code\u003e receives this request and, as designed, authenticates the legitimate low-privilege user, then adds its own \u003ccode\u003eX-Forwarded-User\u003c/code\u003e header (dash variant) reflecting this authenticated identity.\u003c/li\u003e\n\u003cli\u003eHowever, the \u003ccode\u003eoauth-proxy\u003c/code\u003e fails to remove the attacker-supplied \u003ccode\u003eX_Forwarded_User\u003c/code\u003e header (underscore variant) before forwarding the request to the upstream application.\u003c/li\u003e\n\u003cli\u003eThe upstream application (e.g., developed with WSGI or PHP frameworks) receives the request containing both the legitimate \u003ccode\u003eX-Forwarded-User\u003c/code\u003e header from the proxy and the forged \u003ccode\u003eX_Forwarded_User\u003c/code\u003e header from the attacker.\u003c/li\u003e\n\u003cli\u003eDue to internal header normalization logic within these frameworks, both \u003ccode\u003eX-Forwarded-User\u003c/code\u003e and \u003ccode\u003eX_Forwarded_User\u003c/code\u003e are mapped to the same internal variable, with the forged underscore-variant often taking precedence.\u003c/li\u003e\n\u003cli\u003eThe upstream application incorrectly processes the request using the forged, high-privilege identity supplied by the attacker, leading to privilege escalation or unauthorized actions.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-49332 allows an authenticated low-privilege user to effectively impersonate a higher-privileged user in upstream applications. This can lead to unauthorized access to sensitive data, execution of administrative functions, or complete compromise of the affected application's functionality. While the NVD entry does not specify the number of victims or targeted sectors, the vulnerability applies to any deployment of Red Hat OpenShift Container Platform 4 utilizing the \u003ccode\u003eopenshift/oauth-proxy\u003c/code\u003e in conjunction with upstream applications that normalize HTTP header variants. The CVSS v3.1 base score of 8.5 (High) reflects the significant security risk posed by this vulnerability.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch CVE-2026-49332 immediately by applying the latest security updates provided by Red Hat for your affected \u003ccode\u003eRed Hat OpenShift Container Platform 4\u003c/code\u003e installations.\u003c/li\u003e\n\u003cli\u003eRefer to the official Red Hat security advisory at \u003ccode\u003ehttps://access.redhat.com/security/cve/CVE-2026-49332\u003c/code\u003e for detailed patching instructions and mitigation strategies.\u003c/li\u003e\n\u003cli\u003eReview the Red Hat bug report at \u003ccode\u003ehttps://bugzilla.redhat.com/show_bug.cgi?id=2483253\u003c/code\u003e for additional technical details and discussions.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-28T13:20:03Z","date_published":"2026-07-28T13:20:03Z","id":"https://feed.craftedsignal.io/briefs/2026-07-cve-2026-49332/","summary":"A flaw in Red Hat OpenShift's oauth-proxy, tracked as CVE-2026-49332, allows an authenticated low-privilege user to smuggle a forged identity header by exploiting differences in how dash and underscore variants of 'X-Forwarded-User' are handled, potentially leading to privilege escalation in upstream applications.","title":"CVE-2026-49332: OpenShift OAuth Proxy Header Smuggling Vulnerability","url":"https://feed.craftedsignal.io/briefs/2026-07-cve-2026-49332/"}],"language":"en","title":"CraftedSignal Threat Feed - Header-Smuggling","version":"https://jsonfeed.org/version/1.1"}