← Back to CVE List
Vulnerability Intelligence Report
Openshift/oauth-proxy: openshift/oauth-proxy: underscore header smuggling enables identity impersonation on wsgi/php upstreams

CVE-2026-49332

A flaw was found in openshift/oauth-proxy. The proxy sets authenticated identity headers using only dash-variant keys (X-Forwarded-User) but does not strip underscore-variant keys (X_Forwarded_User) from incoming requests. WSGI and PHP frameworks normalize both variants to the same variable, allowing an authenticated low-privilege user to smuggle a forged identity that may override the legitimate authenticated identity in the upstream application.

No Active Exploit Signals
CVSS Base Score
8.5
HIGH
Exploitability:3.2
Impact Score:4.8
EPSS Probability:0.30%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-436 ↗Interpretation Conflict

Affected Products & Versions

Vendor Product Affected Versions
Red Hat Red Hat OpenShift Container Platform 4.12 1786458704 < * (unaffected)
Red Hat Red Hat OpenShift Container Platform 4.13 1786477436 < * (unaffected)
Red Hat Red Hat OpenShift Container Platform 4.14 1785549818 < * (unaffected)
Red Hat Red Hat OpenShift Container Platform 4.15 1787054100 < * (unaffected)
Red Hat Red Hat OpenShift Container Platform 4.16 1785544039 < * (unaffected)
Red Hat Red Hat OpenShift Container Platform 4.17 1787543313 < * (unaffected)
Red Hat Red Hat OpenShift Container Platform 4.18 1785529735 < * (unaffected)
Red Hat Red Hat OpenShift Container Platform 4.19 1785521728 < * (unaffected)
Red Hat Red Hat OpenShift Container Platform 4.20 1785833742 < * (unaffected)
Red Hat Red Hat OpenShift Container Platform 4.21 1785851359 < * (unaffected)
Red Hat Red Hat OpenShift Container Platform 4.22 1785885351 < * (unaffected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
0.301%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityRed Hat, Inc. · Vendor · USA
Reserved2026-05-29T13:28:56
Published2026-07-28T12:18:26
Patch Date2026-07-28
Last Updated2026-09-21T16:09:11

LINK COPIED TO CLIPBOARD