CVE-2026-33495
CVE-2026-33495 is a medium-severity vulnerability in Ory Oathkeeper with a CVSS 3.x base score of 6.5. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-862.
Key facts
- Severity: Medium (CVSS 3.x base score 6.5)
- EPSS exploit prediction: 0% (18th percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2026-16287
- Weakness: CWE-862
- Affected product: Ory Oathkeeper
- Published:
- Last modified:
Description
ORY Oathkeeper is an Identity & Access Proxy (IAP) and Access Control Decision API that authorizes HTTP requests based on sets of Access Rules. Ory Oathkeeper is often deployed behind other components like CDNs, WAFs, or reverse proxies. Depending on the setup, another component might forward the request to the Oathkeeper proxy with a different protocol (http vs. https) than the original request. In order to properly match the request against the configured rules, Oathkeeper considers the `X-Forwarded-Proto` header when evaluating rules. The configuration option `serve.proxy.trust_forwarded_headers` (defaults to false) governs whether this and other `X-Forwarded-*` headers should be trusted. Prior to version 26.2.0, Oathkeeper did not properly respect this configuration, and would always consider the `X-Forwarded-Proto` header. In order for an attacker to abuse this, an installation of Ory Oathkeeper needs to have distinct rules for HTTP and HTTPS requests. Also, the attacker needs to be able to trigger one but not the other rule. In this scenario, the attacker can send the same request but with the `X-Forwarded-Proto` header in order to trigger the other rule. We do not expect many configurations to meet these preconditions. Version 26.2.0 contains a patch. Ory Oathkeeper will correctly respect the `serve.proxy.trust_forwarded_headers` configuration going forward, thereby eliminating the attack scenario. We recommend upgrading to a fixed version even if the preconditions are not met. As an additional mitigation, it is generally recommended to drop any unexpected headers as early as possible when a request is handled, e.g. in the WAF.
Frequently asked questions
- What is CVE-2026-33495?
- ORY Oathkeeper is an Identity & Access Proxy (IAP) and Access Control Decision API that authorizes HTTP requests based on sets of Access Rules. Ory Oathkeeper is often deployed behind other components like CDNs, WAFs, or reverse proxies. Depending on the setup, another component might forward the request to the Oathkeeper proxy with a different protocol (http vs. https) than the original request. In order to properly match the request against the configured rules, Oathkeeper considers the `X-Forwarded-Proto` header when evaluating rules. The configuration option `serve.proxy.trust_forwarded_headers` (defaults to false) governs whether this and other `X-Forwarded-*` headers should be trusted. Prior to version 26.2.0, Oathkeeper did not properly respect this configuration, and would always consider the `X-Forwarded-Proto` header. In order for an attacker to abuse this, an installation of Ory Oathkeeper needs to have distinct rules for HTTP and HTTPS requests. Also, the attacker needs to be able to trigger one but not the other rule. In this scenario, the attacker can send the same request but with the `X-Forwarded-Proto` header in order to trigger the other rule. We do not expect many configurations to meet these preconditions. Version 26.2.0 contains a patch. Ory Oathkeeper will correctly respect the `serve.proxy.trust_forwarded_headers` configuration going forward, thereby eliminating the attack scenario. We recommend upgrading to a fixed version even if the preconditions are not met. As an additional mitigation, it is generally recommended to drop any unexpected headers as early as possible when a request is handled, e.g. in the WAF.
- How severe is CVE-2026-33495?
- CVE-2026-33495 has a CVSS 3.x base score of 6.5, rated medium severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is low, integrity low, and availability none.
- Is CVE-2026-33495 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (18th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-33495?
- CVE-2026-33495 affects Ory Oathkeeper. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2026-33495?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- Does CVE-2026-33495 have an EU (EUVD) identifier?
- Yes. CVE-2026-33495 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2026-16287.
- When was CVE-2026-33495 published?
- CVE-2026-33495 was published on 2026-03-26 and last updated on 2026-06-17.
References
- https://github.com/ory/oathkeeper/commit/e9acca14a04d246250557550065e4b4576525bd5
- https://github.com/ory/oathkeeper/security/advisories/GHSA-vhr5-ggp3-qq85
Affected products (1)
- cpe:2.3:a:ory:oathkeeper:*:*:*:*:*:*:*:*
More vulnerabilities in Ory Oathkeeper
- CVE-2026-33494 — Critical (CVSS 10.0): ORY Oathkeeper is an Identity & Access Proxy (IAP) and Access Control Decision API that authorizes HTTP requests based…
- CVE-2026-33496 — High (CVSS 8.1): ORY Oathkeeper is an Identity & Access Proxy (IAP) and Access Control Decision API that authorizes HTTP requests based…
- CVE-2021-32701 — High (CVSS 7.5): ORY Oathkeeper is an Identity & Access Proxy (IAP) and Access Control Decision API that authorizes HTTP requests based…
All CVEs affecting Ory Oathkeeper →
Other CWE-862 (Missing Authorization) vulnerabilities
- CVE-2026-101000 — Critical (CVSS 10.0): A vulnerability was determined in Netcore NBR100V2 1.3.240614.030928. This affects the function uci.apply of the file…
- CVE-2026-97360 — Critical (CVSS 10.0): HFS2 version 2.4.0 and earlier contains an unauthenticated arbitrary file access vulnerability that allows…
- CVE-2026-65381 — Critical (CVSS 10.0): A validation issue existed in the entitlement verification. This issue was addressed with improved validation of the…
- CVE-2026-81648 — Critical (CVSS 10.0): The CryptoPayment Gateway WordPress plugin from 1.2.1 to 1.2.2 does not apply an authorization check on one of its AJAX…
- CVE-2026-77770 — Critical (CVSS 10.0): The miniOrange 2FA WordPress plugin before 6.3.1, miniOrange 2FA WordPress plugin before 19.3 does not require a…
- CVE-2026-65667 — Critical (CVSS 10.0): Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network.
Browse all CWE-862 (Missing Authorization) vulnerabilities →