PT-2026-26779 · Ory · Ory Oathkeeper

Zepatrik

·

Published

2026-03-20

·

Updated

2026-03-27

·

CVE-2026-33495

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Ory Oathkeeper (affected versions not specified)
Description Ory Oathkeeper, when deployed behind components like CDNs or reverse proxies, may incorrectly evaluate rules due to improper handling of the X-Forwarded-Proto header. The configuration option serve.proxy.trust forwarded headers was not properly respected, leading Oathkeeper to always consider this header, even when it should not. This could allow an attacker to trigger different rules by manipulating the X-Forwarded-Proto header, provided distinct rules exist for HTTP and HTTPS requests and the attacker can trigger one but not the other.
Recommendations Upgrade to a fixed version of Ory Oathkeeper. It is generally recommended to drop any unexpected headers as early as possible when a request is handled, for example, in a WAF.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-33495
GHSA-VHR5-GGP3-QQ85
GO-2026-4810
SUSE-SU-2026:1135-1

Affected Products

Ory Oathkeeper