Session Management Flaw in OAuth2 Proxy Affects User Logout Process
CVE-2026-34454

3.5LOW

Key Information:

Vendor
CVE Published:
14 April 2026

What is CVE-2026-34454?

OAuth2 Proxy, a reverse proxy facilitating authentication with OAuth2 providers, introduced a regression in version 7.11.0 that impacts session management. This flaw prevents the clearing of the session cookie during the rendering of the sign-in page. If users depend on the sign-in page for logging out, they may find the existing session cookie remains valid, allowing unauthorized access on shared devices. It is important for deployments using dedicated logout endpoints to note that they are unaffected. This vulnerability has been rectified in version 7.15.2.

Affected Version(s)

oauth2-proxy >= 7.11.0, < 7.15.2

References

CVSS V3.1

Score:
3.5
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.