NIXPKGS-2026-1115
GitHub issue
published on
Permalink
CVE-2026-34454
3.5 LOW
- CVSS version: 3.1
- Attack vector (AV): PHYSICAL
- Attack complexity (AC): LOW
- Privileges required (PR): NONE
- User interaction (UI): NONE
- Scope (S): UNCHANGED
- Confidentiality impact (C): LOW
- Integrity impact (I): LOW
- Availability impact (A): NONE
by @LeSuisse Activity log
- Created automatic suggestion
- @LeSuisse ignored reference https://g…
- @LeSuisse ignored maintainer @Swarsel maintainer.ignore
- @LeSuisse accepted
- @LeSuisse published on GitHub
OAuth2 Proxy: Session cookie not cleared when rendering sign-in page
OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. A regression introduced in 7.11.0 prevents OAuth2 Proxy from clearing the session cookie when rendering the sign-in page. In deployments that rely on the sign-in page as part of their logout flow, a user may be shown the sign-in page while the existing session cookie remains valid, meaning the browser session is not actually logged out. On shared workstations or devices, a subsequent user could continue to use the previous user's authenticated session. Deployments that use a dedicated logout/sign-out endpoint to terminate sessions are not affected. This issue is fixed in 7.15.2
References
Ignored references (1)
-
https://github.com/oauth2-proxy/oauth2-proxy/releases/tag/v7.15.2 x_refsource_MISC
Affected products
oauth2-proxy
- ==>= 7.11.0, < 7.15.2
Package maintainers
Ignored maintainers (1)
-
@Swarsel Leon Schwarzäugl <leon@swarsel.win>