oauth2-proxy is a widely deployed authentication gateway and reverse proxy that sits in the request path of applications requiring single sign-on and token validation, making it a critical control point for access management. Its vulnerability profile skews toward serious outcomes, concentrated in authentication and authorization weaknesses—including open redirects, authentication bypass via spoofing or alternate paths, CSRF, and improper authorization checks—that reflect the complexity of OAuth2 token handling and session management at the boundary layer. Defenders should treat oauth2-proxy releases as priorities for environments where it guards sensitive applications, since authentication-layer flaws can propagate broadly; live severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Oauth2 Proxy Project over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-40575CRITICAL OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions 7.5.0 through 7.15.1 may trust a client-supplied `X-Forwarded-Uri` header when `--reve | Apr 22, 2026 | 9.1 | 35 | NO | NO |
CVE-2025-54576CRITICAL OAuth2-Proxy is an open-source tool that can act as either a standalone reverse proxy or a middleware component integrated into existing reverse proxy or load balancer setups. In v | Jul 30, 2025 | 9.1 | 35 | NO | NO |
CVE-2026-34457CRITICAL OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions prior to 7.15.2 contain a configuration-dependent authentication bypass in deployments | Apr 14, 2026 | 9.1 | 32 | NO | NO |
CVE-2026-41059HIGH OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions 7.5.0 through 7.15.1 have a configuration-dependent authentication bypass. Deployments | Apr 22, 2026 | 8.2 | 29 | NO | NO |
CVE-2017-1000069HIGH CSRF in Bitly oauth2_proxy 2.1 during authentication flow | Jul 17, 2017 | 8.8 | 24 | NO | NO |
CVE-2026-40574MEDIUM OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Prior to 7.15.2, an authorization bypass exists in OAuth2 Proxy as part of the email_domain enf | Apr 21, 2026 | 6.8 | 22 | NO | NO |
CVE-2021-21291MEDIUM OAuth2 Proxy is an open-source reverse proxy and static file server that provides authentication using Providers (Google, GitHub, and others) to validate accounts by email, domain | Feb 2, 2021 | 6.1 | 20 | NO | NO |
CVE-2020-4037MEDIUM In OAuth2 Proxy from version 5.1.1 and less than version 6.0.0, users can provide a redirect address for the proxy to send the authenticated user to at the end of the authenticatio | Jun 29, 2020 | 5.4 | 20 | NO | NO |
CVE-2021-21411MEDIUM OAuth2-Proxy is an open source reverse proxy that provides authentication with Google, Github or other providers. The `--gitlab-group` flag for group-based authorization in the Git | Mar 26, 2021 | 5.5 | 19 | NO | NO |
CVE-2017-1000070MEDIUM The Bitly oauth2_proxy in version 2.1 and earlier was affected by an open redirect vulnerability during the start and termination of the 2-legged OAuth flow. This issue was caused | Jul 17, 2017 | 6.1 | 19 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Oauth2 Proxy Project.
Media articles that mention a CVE ID that affects a product developed by Oauth2 Proxy Project — matched by CVE ID, not by vendor name.