OVERVIEW CVE-2026-41059 is a configuration-dependent authentication bypass vulnerability in OAuth2 Proxy versions 7.5.0 through 7.15.1. The flaw allows unauthenticated attackers to bypass skip-auth allowlist rules by injecting URL fragments (using # or %23) into crafted requests. Vulnerable deployments must simultaneously use skip_auth_routes or skip_auth_regex features, employ overly broad wildcard patterns, and have upstream applications that interpret fragment delimiters. The vulnerability was patched in version 7.15.2 with more conservative path normalization. SEVERITY This vulnerability carries a CVSS 3.1 score of 8.2 (HIGH) with a network-based attack vector, low complexity, and no authentication requirement. The attack succeeds against unpatched instances without user interaction. Impact includes high confidentiality loss through unauthorized access to protected resources and limited integrity compromise, though availability is not affected. The EPSS score of 0.00133 indicates relatively low exploitation prevalence in the wild compared to other CVEs. EXPLOITATION STATUS There are no indicators of active exploitation or public exploit code availability at this time. The vulnerability is not listed on CISA's Known Exploited Vulnerabilities catalog, and community attention appears limited given the low EPSS percentile ranking. However, organizations using the affected configuration pattern should prioritize upgrading to version 7.15.2 or implementing recommended mitigations such as tightening skip-auth rules, rejecting requests containing fragment characters at network ingress points, or deploying WAF rules to block such requests.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 7.5.0, < 7.15.2CPE matchmatch criteria | cpe:2.3:a:oauth2_proxy_project:oauth2_proxy:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.