Skip to main content

Vendor archive

oauth2_proxy_project CVEs

Beta · best-effort

13 CVEs tagged to vendor oauth2_proxy_project3 Critical, 3 High, 6 Medium, 1 Low, 0 Unrated.

CVE-2026-41059

Published Apr 22, 2026

OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions 7.5.0 through 7.15.1 have a configuration-dependent authentication bypass. Deployment…

CVSS 8.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-40575

Published Apr 22, 2026

OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions 7.5.0 through 7.15.1 may trust a client-supplied `X-Forwarded-Uri` header when `--rev…

CVSS 9.1 · Critical
evidence mentions
4
Buzz score
29.1
Vendor/product tagsBeta · best-effort

CVE-2026-40574

Published Apr 21, 2026

OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Prior to 7.15.2, an authorization bypass exists in OAuth2 Proxy as part of the email_domain en…

CVSS 6.8 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-34457

Published Apr 14, 2026

OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions prior to 7.15.2 contain a configuration-dependent authentication bypass in deployment…

CVSS 9.1 · Critical
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-34454

Published Apr 14, 2026

OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. A regression introduced in 7.11.0 prevents OAuth2 Proxy from clearing the session cookie when…

CVSS 3.5 · Low
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2025-54576

Published Jul 30, 2025

OAuth2-Proxy is an open-source tool that can act as either a standalone reverse proxy or a middleware component integrated into existing reverse proxy or load balancer setups. In…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-21411

Published Mar 26, 2021

OAuth2-Proxy is an open source reverse proxy that provides authentication with Google, Github or other providers. The `--gitlab-group` flag for group-based authorization in the Gi…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-21291

Published Feb 2, 2021

OAuth2 Proxy is an open-source reverse proxy and static file server that provides authentication using Providers (Google, GitHub, and others) to validate accounts by email, domain…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-4037

Published Jun 29, 2020

In OAuth2 Proxy from version 5.1.1 and less than version 6.0.0, users can provide a redirect address for the proxy to send the authenticated user to at the end of the authenticati…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-11053

Published May 7, 2020

In OAuth2 Proxy before 5.1.1, there is an open redirect vulnerability. Users can provide a redirect address for the proxy to send the authenticated user to at the end of the authe…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2020-5233

Published Jan 30, 2020

OAuth2 Proxy before 5.0 has an open redirect vulnerability. Authentication tokens could be silently harvested by an attacker. This has been patched in version 5.0.

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-1000070

Published Jul 17, 2017

The Bitly oauth2_proxy in version 2.1 and earlier was affected by an open redirect vulnerability during the start and termination of the 2-legged OAuth flow. This issue was caused…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-13 of 13 CVEsPage 1 of 1