Database/Control plane, storage & DevOps

OAuth2-Proxy: skip_auth_routes route matching flaw
CVSS 9.1CVE-2025-54576Control plane, storage & DevOpscurated
Impact
skip_auth_routes route matching flaw -> authentication bypass on protected paths
Who can reach it
Network (remote)
What to do
Control-plane: upgrade the ingress auth sidecar; re-audit every skip rule
References
Related entries
- Apache Airflow: logout does not invalidate the session JWT, so an intercepted token stays usableCVE-2025-57735 · Apache Airflow (API server JWT session handling on logout)Critical
- HashiCorp Vault: Root-namespace operator with write on sys/audit gains code execution on the Vault hostCVE-2025-6000 · HashiCorp VaultCritical
- Lantronix EDS3000PS serial-to-Ethernet device server: Full bypass of the management-page loginCVE-2025-67039 · Lantronix EDS3000PS serial-to-Ethernet device serverCritical
- Palo Alto PAN-OS: GlobalProtect portal/gateway auth bypassCVE-2026-0257 · Palo Alto PAN-OSCritical
- Grafana MCP Server: caller-controlled X-Grafana-URL header turns grafana_api_request into a full SSRF primitiveCVE-2026-19516 · mcp-grafana (Grafana MCP Server, X-Grafana-URL destination control)Critical
- Apache CloudStack Proxmox extension (cross-tenant instance access): The extension keys CloudStack instances to ProxmoxCVE-2026-25199 · Apache CloudStack Proxmox extension (cross-tenant instance access)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.