Authorization Bypass in OAuth2 Proxy Affects Email Domain Enforcement
CVE-2026-40574
6.8MEDIUM
What is CVE-2026-40574?
OAuth2 Proxy, a reverse proxy that authenticates using OAuth2 providers, contains a vulnerability that allows authorization bypass through improperly validated email claims. An attacker can exploit the email_domain enforcement option, allowing them to authenticate with malformed email addresses that meet domain requirements, such as 'attacker@evil.com@company.com'. This flaw poses a risk particularly to deployments depending on email domain restrictions that accept claims lacking strict email syntax validation. The vulnerability was addressed in version 7.15.2.
Affected Version(s)
oauth2-proxy < 7.15.2
