Skip to content

Authorization Bypass in Email Domain Validation via Malformed Multi-@ Email Claims

Moderate
tuunit published GHSA-c5c4-8r6x-56w3 Apr 14, 2026

Package

No package listed

Affected versions

< 7.15.2

Patched versions

> 7.15.1

Description

Impact

An authorization bypass exists in OAuth2 Proxy as part of the email_domain
enforcement option. An attacker may be able to authenticate with an email
claim such as [email protected]@company.com and satisfy an allowed
domain check for company.com, even though the claim is not a valid email
address.

The issue ONLY affects deployments that rely on email_domain restrictions
and accept email claim values from identity providers or claim mappings that do
not strictly enforce normal email syntax. The practical risk ONLY exists in
self-hosted or custom OIDC environments and federated setups where
unexpected claim values can reach oauth2-proxy. Standard hosted providers
that enforce valid email formatting ARE NOT effected.

Patches

Users should upgrade to v7.15.2 or later once available.

Workarounds

The most effective workaround is to ensure the configured identity provider
cannot emit malformed or attacker-controlled email claim values.

Severity

Moderate

CVSS overall score

This score calculates overall vulnerability severity from 0 to 10 and is based on the Common Vulnerability Scoring System (CVSS).
/ 10

CVSS v3 base metrics

Attack vector
Network
Attack complexity
High
Privileges required
Low
User interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None

CVSS v3 base metrics

Attack vector: More severe the more the remote (logically and physically) an attacker can be in order to exploit the vulnerability.
Attack complexity: More severe for the least complex attacks.
Privileges required: More severe if no privileges are required.
User interaction: More severe when no user interaction is required.
Scope: More severe when a scope change occurs, e.g. one vulnerable component impacts resources in components beyond its security scope.
Confidentiality: More severe when loss of data confidentiality is highest, measuring the level of data access available to an unauthorized user.
Integrity: More severe when loss of data integrity is the highest, measuring the consequence of data modification possible by an unauthorized user.
Availability: More severe when the loss of impacted component availability is highest.
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N

CVE ID

CVE-2026-40574

Weaknesses

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly. Learn more on MITRE.

Credits