CVE-2026-40574 — Incorrect Authorization in Oauth2-proxy Oauth2-proxy V7
Severity
—MEDIUM
No vectorEPSS
No EPSS data
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 15
Description
OAuth2 Proxy has an Authorization Bypass in Email Domain Validation via Malformed Multi-@ Email Claims
### Impact
An authorization bypass exists in OAuth2 Proxy as part of the `email_domain` enforcement option. An attacker may be able to authenticate with an email claim such as `[email protected]@company.com` and satisfy an allowed domain check for `company.com`, even though the claim is not a valid email address.
The issue **ONLY** affects deployments that rely on `email_domain` restrictions…
Affected Packages1 packages
🔴Vulnerability Details
1GHSA▶
OAuth2 Proxy has an Authorization Bypass in Email Domain Validation via Malformed Multi-@ Email Claims↗2026-04-15