Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Oauth2 Proxy Project

First CVE: Jul 17, 2017Active for: 9 yearsTotal CVEs: 13
26.3
VTI Score
Low

oauth2-proxy is a widely deployed authentication gateway and reverse proxy that sits in the request path of applications requiring single sign-on and token validation, making it a critical control point for access management. Its vulnerability profile skews toward serious outcomes, concentrated in authentication and authorization weaknesses—including open redirects, authentication bypass via spoofing or alternate paths, CSRF, and improper authorization checks—that reflect the complexity of OAuth2 token handling and session management at the boundary layer. Defenders should treat oauth2-proxy releases as priorities for environments where it guards sensitive applications, since authentication-layer flaws can propagate broadly; live severity and exploitation figures are shown alongside this summary.

FAUCET AI Generated
13
Total CVEs
More Total CVEs than 94% of tracked vendors
2.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 91% of tracked vendors
6.9
Avg CVSS Score
Higher Avg CVSS Score than 49% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Oauth2 Proxy Project over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 17, 2017
9 years ago
Most Recent CVE
Apr 22, 2026
93 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (13 CVEs).

13 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-40575CRITICAL
OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions 7.5.0 through 7.15.1 may trust a client-supplied `X-Forwarded-Uri` header when `--reve
Apr 22, 20269.135NONO
CVE-2025-54576CRITICAL
OAuth2-Proxy is an open-source tool that can act as either a standalone reverse proxy or a middleware component integrated into existing reverse proxy or load balancer setups. In v
Jul 30, 20259.135NONO
CVE-2026-34457CRITICAL
OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions prior to 7.15.2 contain a configuration-dependent authentication bypass in deployments
Apr 14, 20269.132NONO
CVE-2026-41059HIGH
OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions 7.5.0 through 7.15.1 have a configuration-dependent authentication bypass. Deployments
Apr 22, 20268.229NONO
CVE-2017-1000069HIGH
CSRF in Bitly oauth2_proxy 2.1 during authentication flow
Jul 17, 20178.824NONO
CVE-2026-40574MEDIUM
OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Prior to 7.15.2, an authorization bypass exists in OAuth2 Proxy as part of the email_domain enf
Apr 21, 20266.822NONO
CVE-2021-21291MEDIUM
OAuth2 Proxy is an open-source reverse proxy and static file server that provides authentication using Providers (Google, GitHub, and others) to validate accounts by email, domain
Feb 2, 20216.120NONO
CVE-2020-4037MEDIUM
In OAuth2 Proxy from version 5.1.1 and less than version 6.0.0, users can provide a redirect address for the proxy to send the authenticated user to at the end of the authenticatio
Jun 29, 20205.420NONO
CVE-2021-21411MEDIUM
OAuth2-Proxy is an open source reverse proxy that provides authentication with Google, Github or other providers. The `--gitlab-group` flag for group-based authorization in the Git
Mar 26, 20215.519NONO
CVE-2017-1000070MEDIUM
The Bitly oauth2_proxy in version 2.1 and earlier was affected by an open redirect vulnerability during the start and termination of the 2-legged OAuth flow. This issue was caused
Jul 17, 20176.119NONO
View all 13 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products13 CVEs
54%
15%
23%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network12 (92.3%)
Unknown0 (0.0%)
Physical1 (7.7%)
Adjacent Network0 (0.0%)
Attack Complexity
Low12 (92.3%)
High1 (7.7%)
Unknown0 (0.0%)
User Interaction
None7 (53.8%)
Unknown0 (0.0%)
Required6 (46.2%)
Privileges Required
Low1 (7.7%)
High1 (7.7%)
None11 (84.6%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (13 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Oauth2 Proxy Project.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Oauth2 Proxy Project — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Oauth2 Proxy Project's Products

View all 2 CNAs →

Top CWEs