CVE-2026-34454Oauth2_proxy_project · Oauth2_proxy
Vulnerability data via NVD (ingested)
OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. A regression introduced in 7.11.0 prevents OAuth2 Proxy from clearing the session cookie when rendering the sign-in page. In deployments that rely on the sign-in page as part of their logout flow, a user may be shown the sign-in page while the existing session cookie remains valid, meaning the browser session is not actually logged out. On shared workstations or devices, a subsequent user could continue to use the previous user's authenticated session. Deployments that use a dedicated logout/sign-out endpoint to terminate sessions are not affected. This issue is fixed in 7.15.2
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
vuln:CVE-2026-34454product:"Oauth2 Proxy Project Oauth2 Proxy"http.html:"Oauth2 Proxy"More intel sources (5)
vuln:CVE-2026-34454vulnerabilities.cve_id: CVE-2026-34454CVE-2026-34454CVE-2026-34454"CVE-2026-34454" exploit -site:nvd.nist.gov