Session Management Flaw in OAuth2 Proxy Affects User Logout Process
CVE-2026-34454
3.5LOW
What is CVE-2026-34454?
OAuth2 Proxy, a reverse proxy facilitating authentication with OAuth2 providers, introduced a regression in version 7.11.0 that impacts session management. This flaw prevents the clearing of the session cookie during the rendering of the sign-in page. If users depend on the sign-in page for logging out, they may find the existing session cookie remains valid, allowing unauthorized access on shared devices. It is important for deployments using dedicated logout endpoints to note that they are unaffected. This vulnerability has been rectified in version 7.15.2.
Affected Version(s)
oauth2-proxy >= 7.11.0, < 7.15.2
