VDB
CVE-2026-49332
CVE-2026-49332
PUBLISHED
CVSS 8.5 HIGH
Reported by redhat · Published July 28, 2026
A flaw was found in openshift/oauth-proxy. The proxy sets authenticated identity headers using only dash-variant keys (X-Forwarded-User) but does not strip underscore-variant keys (X_Forwarded_User) from incoming requests. WSGI and PHP frameworks normalize both variants to the same variable, allowing an authenticated low-privilege user to smuggle a forged identity that may override the legitimate authenticated identity in the upstream application.
Risk Scores
CVSS 3.1
8.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat OpenShift Container Platform 4.12 | 1786458704 |
| Red Hat | Red Hat OpenShift Container Platform 4.13 | 1786477436 |
| Red Hat | Red Hat OpenShift Container Platform 4.14 | 1785549818 |
| Red Hat | Red Hat OpenShift Container Platform 4.15 | 1787054100 |
| Red Hat | Red Hat OpenShift Container Platform 4.16 | 1785544039 |
| Red Hat | Red Hat OpenShift Container Platform 4.18 | 1785529735 |
| Red Hat | Red Hat OpenShift Container Platform 4.19 | 1785521728 |
| Red Hat | Red Hat OpenShift Container Platform 4.20 | 1785833742 |
| Red Hat | Red Hat OpenShift Container Platform 4.21 | 1785851359 |
| Red Hat | Red Hat OpenShift Container Platform 4.22 | 1785885351 |
| Red Hat | Red Hat OpenShift Container Platform 4.19 | 1785521728, 1785521728, 1785521728 |
| Red Hat | Red Hat OpenShift Container Platform 4.18 | 1785529735, 1785529735, 1785529735 |
| Red Hat | Red Hat OpenShift Container Platform 4.14 | 1785549818, 1785549818, 1785549818 |
| Red Hat | Red Hat OpenShift Container Platform 4.15 | 1787054100 |
| Red Hat | Red Hat OpenShift Container Platform 4 | |
| Red Hat | Red Hat OpenShift Container Platform 4.2 | 1785833742, 1785833742, 1785833742 |
| Red Hat | Red Hat OpenShift Container Platform 4.20 | 1785833742, 1785833742, 1785833742 |
| Red Hat | Red Hat OpenShift Container Platform 4.21 | 1785851359, 1785851359, 1785851359 |
| Red Hat | Red Hat OpenShift Container Platform 4.22 | 1785885351, 1785885351, 1785885351 |
| Red Hat | Red Hat OpenShift Container Platform 4.16 | 1785544039, 1785544039, 1785544039 |
…and 3 more
Timeline
- Jul 28, 2026 CVE Published
- Jul 29, 2026 Coalition ESS Score
- Aug 7, 2026 EPSS Score
- Aug 24, 2026 EPSS Score
- Aug 26, 2026 CVE Updated
- Aug 27, 2026 Distribution Patch
- Aug 27, 2026 Distribution Patch
- Aug 27, 2026 Distribution Patch
- Aug 27, 2026 Distribution Patch
- Aug 27, 2026 Distribution Patch
- Aug 27, 2026 Distribution Patch
- Aug 27, 2026 Distribution Patch
References
- RHSA-2026:50681 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:50758 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:51007 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:51013 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:51022 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:51025 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:51038 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:54188 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:54206 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:56912 vendor-advisoryx_refsource_REDHAT
- vdb-entryx_refsource_REDHAT
- RHBZ#2483253 issue-trackingx_refsource_REDHAT