Vulnerability Intelligence Report
Openshift/oauth-proxy: openshift/oauth-proxy: underscore header smuggling enables identity impersonation on wsgi/php upstreams
CVE-2026-49332
A flaw was found in openshift/oauth-proxy. The proxy sets authenticated identity headers using only dash-variant keys (X-Forwarded-User) but does not strip underscore-variant keys (X_Forwarded_User) from incoming requests. WSGI and PHP frameworks normalize both variants to the same variable, allowing an authenticated low-privilege user to smuggle a forged identity that may override the legitimate authenticated identity in the upstream application.
No Active Exploit Signals
CVSS Base Score
8.5
HIGH
Exploitability:3.2
Impact Score:4.8
EPSS Probability:0.30%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-436 ↗Interpretation Conflict
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Red Hat | Red Hat OpenShift Container Platform 4.12 | 1786458704 < * (unaffected) |
| Red Hat | Red Hat OpenShift Container Platform 4.13 | 1786477436 < * (unaffected) |
| Red Hat | Red Hat OpenShift Container Platform 4.14 | 1785549818 < * (unaffected) |
| Red Hat | Red Hat OpenShift Container Platform 4.15 | 1787054100 < * (unaffected) |
| Red Hat | Red Hat OpenShift Container Platform 4.16 | 1785544039 < * (unaffected) |
| Red Hat | Red Hat OpenShift Container Platform 4.17 | 1787543313 < * (unaffected) |
| Red Hat | Red Hat OpenShift Container Platform 4.18 | 1785529735 < * (unaffected) |
| Red Hat | Red Hat OpenShift Container Platform 4.19 | 1785521728 < * (unaffected) |
| Red Hat | Red Hat OpenShift Container Platform 4.20 | 1785833742 < * (unaffected) |
| Red Hat | Red Hat OpenShift Container Platform 4.21 | 1785851359 < * (unaffected) |
| Red Hat | Red Hat OpenShift Container Platform 4.22 | 1785885351 < * (unaffected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
0.301%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Red Hat, Inc. · Vendor · USA |
| Reserved | 2026-05-29T13:28:56 |
| Published | 2026-07-28T12:18:26 |
| Patch Date | 2026-07-28 |
| Last Updated | 2026-09-21T16:09:11 |
Community Chatter & Buzz