# OAuth2-Proxy skip_auth_routes regex matches the full URI

Source: https://startwithidentity.com/cves/cve-2025-54576/
Last updated: 2026-08-29
License: content by Start with Identity. Cite the source URL.

---

## What broke

[OAuth2-Proxy](https://github.com/oauth2-proxy/oauth2-proxy) compared `skip_auth_routes` regular expressions to the full request URI, query string included. An attacker who could add a query parameter that matched a skip rule reached a protected path without a session. CVSS 9.1. Patched in the upstream project.

## Why it matters

OAuth2-Proxy is the default identity sidecar in a lot of Kubernetes and internal-tool deployments. A skip-list bypass is a full authentication bypass for every app behind that proxy. The failure mode is classic: a convenience regex, a forgotten query string, a production allow-list that was meant for `/metrics` and accidentally matched `?foo=/metrics`.

## What to do

- Upgrade OAuth2-Proxy and re-read every `skip_auth_routes` entry. Match on path only.
- Prefer an explicit allow-list of path prefixes over a regex.
- Confirm `/metrics`, `/health`, and callback URLs cannot be smuggled as query values on admin routes.

## After you patch

Token-layer flaws produce credentials that keep working after the patch, so remediation is about invalidating what was issued.

- **Rotate the signing keys** published at your [JWKS](https://startwithidentity.com/glossary/jwks/) endpoint, then confirm relying parties refetch on an unknown key id rather than caching indefinitely.
- **Revoke [refresh tokens](https://startwithidentity.com/glossary/refresh-token/) and sessions.** Access tokens expire on their own; refresh tokens are the ones that turn a short compromise into months of access.
- **Audit client registrations and consent grants** created during the window, particularly any client with broad scopes or a redirect URI you do not recognize.
- **Verify validation on your side**: pinned algorithms, issuer and audience checks, and no acceptance of `alg: none`. See [JWT](https://startwithidentity.com/glossary/jwt/) and the [validate a JWT recipe](https://startwithidentity.com/recipes/validate-a-jwt/).

## Sources

- [NVD: CVE-2025-54576](https://nvd.nist.gov/vuln/detail/CVE-2025-54576)
