Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-49332— Openshift/oauth-proxy: openshift/oauth-proxy: underscore header smuggling enables identity impersonation on wsgi/php upstreams

Quick assessment

Affected
Red Hat Red Hat OpenShift Container Platform 4.12
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

OpenShift oauth-proxy是OpenShift公司的一款OAuth代理服务器软件。 OpenShift oauth-proxy存在处理逻辑错误漏洞,该漏洞源于代理设置身份验证头时只使用短横线变体键(X-Forwarded-User),但未去除下划线变体键(X_Forwarded_User),导致WSGI和PHP框架将两者标准化为同一变量,允许已认证的低权限用户走私伪造身份,可能覆盖上游应用中的合法身份。

CVSS 8.5 · High EPSS 0.30% · P23

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 11

Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-49332

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Openshift/oauth-proxy: openshift/oauth-proxy: underscore header smuggling enables identity impersonation on wsgi/php upstreams
Source: CVE Program / CVE List V5
Vulnerability Description
A flaw was found in openshift/oauth-proxy. The proxy sets authenticated identity headers using only dash-variant keys (X-Forwarded-User) but does not strip underscore-variant keys (X_Forwarded_User) from incoming requests. WSGI and PHP frameworks normalize both variants to the same variable, allowing an authenticated low-privilege user to smuggle a forged identity that may override the legitimate authenticated identity in the upstream application.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
解释冲突
Source: CVE Program / CVE List V5
Vulnerability Title
OpenShift oauth-proxy 处理逻辑错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
OpenShift oauth-proxy是OpenShift公司的一款OAuth代理服务器软件。 OpenShift oauth-proxy存在处理逻辑错误漏洞,该漏洞源于代理设置身份验证头时只使用短横线变体键(X-Forwarded-User),但未去除下划线变体键(X_Forwarded_User),导致WSGI和PHP框架将两者标准化为同一变量,允许已认证的低权限用户走私伪造身份,可能覆盖上游应用中的合法身份。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Red Hat Red Hat OpenShift Container Platform 4.12 1786458704 ~ * cpe:/a:redhat:openshift:4.12::el9
Red Hat Red Hat OpenShift Container Platform 4.13 1786477436 ~ * cpe:/a:redhat:openshift:4.13::el9
Red Hat Red Hat OpenShift Container Platform 4.14 1785549818 ~ * cpe:/a:redhat:openshift:4.14::el9
Red Hat Red Hat OpenShift Container Platform 4.15 1787054100 ~ * cpe:/a:redhat:openshift:4.15::el9
Red Hat Red Hat OpenShift Container Platform 4.16 1785544039 ~ * cpe:/a:redhat:openshift:4.16::el9
Red Hat Red Hat OpenShift Container Platform 4.17 1787543313 ~ * cpe:/a:redhat:openshift:4.17::el9
Red Hat Red Hat OpenShift Container Platform 4.18 1785529735 ~ * cpe:/a:redhat:openshift:4.18::el9
Red Hat Red Hat OpenShift Container Platform 4.19 1785521728 ~ * cpe:/a:redhat:openshift:4.19::el9
Red Hat Red Hat OpenShift Container Platform 4.20 1785833742 ~ * cpe:/a:redhat:openshift:4.20::el9
Red Hat Red Hat OpenShift Container Platform 4.21 1785851359 ~ * cpe:/a:redhat:openshift:4.21::el9
Red Hat Red Hat OpenShift Container Platform 4.22 1785885351 ~ * cpe:/a:redhat:openshift:4.22::el9

II. Public POCs for CVE-2026-49332

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-49332

登录查看更多情报信息。

Vendor Advisories for CVE-2026-49332 (13)

Same Patch Batch · Red Hat · 2026-07-28 · 5 CVEs total

CVE-2026-18107 7.8 HIGH Criu: criu: container escape via rseq critical section hijack during checkpoint/restore
CVE-2026-16313 7.6 HIGH Sg3_utils: sg3_utils: arbitrary command execution via udev property injection in sg_inq --
CVE-2026-18047 6.5 MEDIUM Dogtag-pki: pki-core: redhat-pki: pki: acme admin enable/disable endpoint authentication b
CVE-2026-17072 3.3 LOW Gstreamer1-plugins-good: gst-plugins-good: 4-byte heap over-read in gst_matroska_parse_fla

IV. Related Vulnerabilities

V. Comments for CVE-2026-49332

No comments yet


Leave a comment