CVE-2025-64484 affects OAuth2-Proxy versions prior to 7.13.0, specifically when deployed with upstream applications that normalize underscores to dashes in HTTP headers (e.g., Django, Flask). Authenticated users can bypass proxy filtering by injecting underscore variants of X-Forwarded-* headers, potentially leading to privilege escalation within the upstream application. This vulnerability has a high CVSS score of 8.5, indicating a network-based attack with low complexity and high impact on confidentiality. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Oauth2-Proxy | Oauth2-Proxy | < 7.13.0CNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.