Detects OAuth2 Proxy instances before 7.15.2 where setting the User-Agent header to the health check value (GoogleHC/1.0) bypasses authentication on any URL path. An unauthenticated attacker gains full access to all upstream services behind the proxy.
Is your app exploitable through CVE-2026-34457?
Scan your domain free