VDB

GCVE-110-CLOUD-2023-0027

GCVE-110-CLOUD-2023-0027
Advisory Published
Vulnetix · Advisory published June 21, 2023
A critical authentication bypass vulnerability was discovered in Google Cloud API Gateway, affecting its JWT authentication method. The flaw, stemming from a business logic bug in the ESPv2 service proxy, allowed attackers to bypass authentication controls by manipulating HTTP methods. This vulnerability impacted various authentication methods including Firebase, Auth0, Okta, and Google ID tokens.

Affected Products

VendorProductVersionsPlatforms
GCPCloud Services
GCPAPI Gateway, Cloud Run, App Engine, Cloud Functions

Browse GCVE Records

73,873 records in the GCVE database · Updated July 20, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›