All verified exploits

CVE-2026-34457 Health Check User-Agent Authentication Bypass

Deterministic critical OAuth2 Proxy Added cve-verified-cve-2026-34457

Detects OAuth2 Proxy instances before 7.15.2 where setting the User-Agent header to the health check value (GoogleHC/1.0) bypasses authentication on any URL path. An unauthenticated attacker gains full access to all upstream services behind the proxy.

Is your app exploitable through CVE-2026-34457?

Scan your domain free