VDB

CVE-2026-49332

CVE-2026-49332 PUBLISHED CVSS 8.5 HIGH

Reported by redhat · Published July 28, 2026

A flaw was found in openshift/oauth-proxy. The proxy sets authenticated identity headers using only dash-variant keys (X-Forwarded-User) but does not strip underscore-variant keys (X_Forwarded_User) from incoming requests. WSGI and PHP frameworks normalize both variants to the same variable, allowing an authenticated low-privilege user to smuggle a forged identity that may override the legitimate authenticated identity in the upstream application.

Risk Scores

CVSS 3.1
8.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N

Affected Products

VendorProductVersions
Red HatRed Hat OpenShift Container Platform 4.121786458704
Red HatRed Hat OpenShift Container Platform 4.131786477436
Red HatRed Hat OpenShift Container Platform 4.141785549818
Red HatRed Hat OpenShift Container Platform 4.151787054100
Red HatRed Hat OpenShift Container Platform 4.161785544039
Red HatRed Hat OpenShift Container Platform 4.181785529735
Red HatRed Hat OpenShift Container Platform 4.191785521728
Red HatRed Hat OpenShift Container Platform 4.201785833742
Red HatRed Hat OpenShift Container Platform 4.211785851359
Red HatRed Hat OpenShift Container Platform 4.221785885351
Red HatRed Hat OpenShift Container Platform 4.191785521728, 1785521728, 1785521728
Red HatRed Hat OpenShift Container Platform 4.181785529735, 1785529735, 1785529735
Red HatRed Hat OpenShift Container Platform 4.141785549818, 1785549818, 1785549818
Red HatRed Hat OpenShift Container Platform 4.151787054100
Red HatRed Hat OpenShift Container Platform 4
Red HatRed Hat OpenShift Container Platform 4.21785833742, 1785833742, 1785833742
Red HatRed Hat OpenShift Container Platform 4.201785833742, 1785833742, 1785833742
Red HatRed Hat OpenShift Container Platform 4.211785851359, 1785851359, 1785851359
Red HatRed Hat OpenShift Container Platform 4.221785885351, 1785885351, 1785885351
Red HatRed Hat OpenShift Container Platform 4.161785544039, 1785544039, 1785544039

…and 3 more

Timeline

  • Jul 28, 2026 CVE Published
  • Jul 29, 2026 Coalition ESS Score
  • Aug 7, 2026 EPSS Score
  • Aug 24, 2026 EPSS Score
  • Aug 26, 2026 CVE Updated
  • Aug 27, 2026 Distribution Patch
  • Aug 27, 2026 Distribution Patch
  • Aug 27, 2026 Distribution Patch
  • Aug 27, 2026 Distribution Patch
  • Aug 27, 2026 Distribution Patch
  • Aug 27, 2026 Distribution Patch
  • Aug 27, 2026 Distribution Patch

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›