---
id: CVE-2025-54576
title: >-
  github.com/oauth2-proxy/oauth2-proxy: OAuth2-Proxy authentication bypass
  (CVE-2025-54576)
summary: >-
  An authentication bypass flaw was found in the OAuth2-Proxy project. This
  bypass affects systems that have configured their deployment to skip
  authentication on endpoints that match a deployment-defined regular
  expression. HTTP parameters …
severity: high
cvss: 7.4
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'
cvssSource: vendor
cwe: CWE-290
vendor: Red Hat
product: Red Hat Ceph Storage 8
affected:
  - ceph_storage 8
patched:
  - github.com/oauth2-proxy/oauth2-proxy/v7 7.11.0
published: '2025-07-30'
updated: '2026-09-23'
sourceUpdated: '2026-09-23T03:20:39+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-54576.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-54576.json
  - url: 'https://access.redhat.com/security/cve/CVE-2025-54576'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2385267'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2025-54576'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2025-54576'
  - url: >-
      https://github.com/oauth2-proxy/oauth2-proxy/blob/f4b33b64bd66ad28e9b0d63bea51837b83c00ca1/oauthproxy.go#L582-L584
  - url: >-
      https://github.com/oauth2-proxy/oauth2-proxy/blob/f4b33b64bd66ad28e9b0d63bea51837b83c00ca1/pkg/requests/util/util.go#L37-L44
  - url: >-
      https://github.com/oauth2-proxy/oauth2-proxy/commit/9ffafad4b2d2f9f7668e5504565f356a7c047b77
  - url: 'https://github.com/oauth2-proxy/oauth2-proxy/releases/tag/v7.11.0'
  - url: >-
      https://github.com/oauth2-proxy/oauth2-proxy/security/advisories/GHSA-7rh7-c77v-6434
  - url: >-
      https://oauth2-proxy.github.io/oauth2-proxy/configuration/overview/#proxy-options
  - url: 'https://github.com/oauth2-proxy/oauth2-proxy'
tags:
  - csaf
  - vex
  - red-hat
  - osv
  - go
epss: 0.01174
epssPercentile: 0.6613
aliases:
  - GHSA-7rh7-c77v-6434
  - BIT-oauth2-proxy-2025-54576
  - GO-2025-3833
ecosystem: go
scores:
  vendor: 7.4
  osv: 9.1
ingestedAt: '2026-09-12T03:13:01.765Z'
---

## Overview

An authentication bypass flaw was found in the OAuth2-Proxy project. This bypass affects systems that have configured their deployment to skip authentication on endpoints that match a deployment-defined regular expression. HTTP parameters can be used to match and trigger the authentication bypass in unexpected ways.

## Vendor advisories

- **Red Hat VEX** · Important · affected: Red Hat Ceph Storage 8 · no fix planned: Red Hat Ceph Storage 8 · updated 2026-09-23 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-54576.json)

**github.com/oauth2-proxy/oauth2-proxy: OAuth2-Proxy authentication bypass** — rated Important by Red Hat. Released 2025-07-30, updated 2026-09-23.

Affected:

- Red Hat Ceph Storage 8

No fix planned:

- Red Hat Ceph Storage 8

## Remediation

Affected

Workarounds / mitigations:

- Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

## Package advisory (CVE-2025-54576)

Affected packages:

- `github.com/oauth2-proxy/oauth2-proxy/v7 < 7.11.0`

Patched in:

- `github.com/oauth2-proxy/oauth2-proxy/v7 7.11.0`

Source: https://osv.dev/vulnerability/GHSA-7rh7-c77v-6434
