vulns.co
/
GKData.io MCP

OAuth2 Proxy · 2 min read

OAuth2 Proxy: client-address provenance must precede authentication exemptions

GHSA-wr5q-7wxw-x568 describes client-address metadata acquiring authority to waive authentication without verified transport-peer and intermediary provenance. The maintainer reports unauthenticated access within the authority already granted by configured address exemptions. This requires optional trusted-address exemptions, reverse-proxy mode and client-controlled address metadata reaching the decision. The educational focus is the authority of an exception path.

Open the reference Maintainer AdvisoryReviewed 2026-10-04

How to use this reference

The v7.15.5 release describes transport-peer verification, bounded intermediary trust and safe failure when trusted-intermediary address metadata is missing or malformed. Upgrading alone is insufficient: compatibility defaults retain overly broad proxy trust. Deployments retaining exemptions must narrowly scope trusted intermediaries and ensure ingress establishes trustworthy address metadata. The advisory recommends removing the exemptions as a workaround. Editorial lesson: treat an authentication exception as an authorization mechanism with its own evidence requirements. Record who can assert each decision-relevant attribute, what authority it can unlock, and what happens when its provenance is unavailable. Patch verification must cover effective configuration as well as installed version; a code change cannot establish a trust boundary that deployment policy leaves universal.

Before reading

  • Reverse-proxy, transport-peer and forwarded-metadata concepts
  • Authentication exemptions and attribute-based authorization concepts

Context and limits

  • Affected-version metadata lists 6.1.0 through 7.15.3, patched-version metadata says later than 7.15.4, and the advisory body names 7.15.5. This gap does not establish 7.15.4 as unaffected.
  • The release API records v7.15.5 publication at 2026-10-01T09:05:48Z. This is software-release chronology, not the educational resource's edition date or proof of deployment remediation.
  • The advisory credits gronke, SmylerMC, etsubu, SnailSploit and ihopenre-eng as reporters. Publishing account tuunit is not an established byline; authors remain unassigned.
  • The sources establish neither universal deployment exposure, downstream account takeover, a production incident nor an award. The advisory lists no known CVE; unrelated release CVEs are not assigned to this record.

Sources and provenance

  1. OAuth2 Proxy client-address authentication-exemption advisory GHSA-wr5q-7wxw-x568 OAuth2 Proxy · reviewed 2026-10-04
  2. OAuth2 Proxy v7.15.5 release notes OAuth2 Proxy · reviewed 2026-10-04
  3. OAuth2 Proxy v7.15.5 official release metadata OAuth2 Proxy · reviewed 2026-10-04

Record reviewed 2026-10-04. Snapshot 53796974ace8. Open the complete JSON contract.

GitHub snapshot 2026-10-04

53796974ace8 · JSON exports & schemas · CC BY 4.0 content / MIT software