IncidentOAuth2-proxy Authentication Bypass: A Header Smuggling Breakdown
A single HTTP header with an underscore instead of a hyphen bypassed authentication for an entire OAuth2-proxy deployment. No brute force. No stolen credentials. Just X_Forwarded_User instead of X-For














