Oauth2 Proxy
Vendor:
First CVE: Jul 17, 2017 · Active for 9 years
13
Total CVEs
More Total CVEs than 91% of tracked products
2.6
Avg CVEs / Year
Higher CVE frequency than 75% of tracked products
6.9
Avg CVSS
Higher Avg CVSS than 40% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Oauth2 Proxy over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 17, 2017
9 years ago
Most Recent CVE
Apr 22, 2026
93 days ago
CVE Severity & Scoring
Oauth2 Proxy13 CVEs
54%
15%
23%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network12 (92.3%)
Unknown0 (0.0%)
Physical1 (7.7%)
Adjacent Network0 (0.0%)
Attack Complexity
Low12 (92.3%)
High1 (7.7%)
Unknown0 (0.0%)
User Interaction
None7 (53.8%)
Unknown0 (0.0%)
Required6 (46.2%)
Privileges Required
Low1 (7.7%)
High1 (7.7%)
None11 (84.6%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-40575CRITICAL OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions 7.5.0 through 7.15.1 may trust a client-supplied `X-Forwarded-Uri` header when `--reve | Apr 22, 2026 | 9.1 | 35 | NO | NO |
CVE-2025-54576CRITICAL OAuth2-Proxy is an open-source tool that can act as either a standalone reverse proxy or a middleware component integrated into existing reverse proxy or load balancer setups. In v | Jul 30, 2025 | 9.1 | 35 | NO | NO |
CVE-2026-34457CRITICAL OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions prior to 7.15.2 contain a configuration-dependent authentication bypass in deployments | Apr 14, 2026 | 9.1 | 32 | NO | NO |
CVE-2026-41059HIGH OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions 7.5.0 through 7.15.1 have a configuration-dependent authentication bypass. Deployments | Apr 22, 2026 | 8.2 | 29 | NO | NO |
CVE-2017-1000069HIGH CSRF in Bitly oauth2_proxy 2.1 during authentication flow | Jul 17, 2017 | 8.8 | 24 | NO | NO |
CVE-2026-40574MEDIUM OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Prior to 7.15.2, an authorization bypass exists in OAuth2 Proxy as part of the email_domain enf | Apr 21, 2026 | 6.8 | 22 | NO | NO |
CVE-2021-21291MEDIUM OAuth2 Proxy is an open-source reverse proxy and static file server that provides authentication using Providers (Google, GitHub, and others) to validate accounts by email, domain | Feb 2, 2021 | 6.1 | 20 | NO | NO |
CVE-2020-4037MEDIUM In OAuth2 Proxy from version 5.1.1 and less than version 6.0.0, users can provide a redirect address for the proxy to send the authenticated user to at the end of the authenticatio | Jun 29, 2020 | 5.4 | 20 | NO | NO |
CVE-2021-21411MEDIUM OAuth2-Proxy is an open source reverse proxy that provides authentication with Google, Github or other providers. The `--gitlab-group` flag for group-based authorization in the Git | Mar 26, 2021 | 5.5 | 19 | NO | NO |
CVE-2017-1000070MEDIUM The Bitly oauth2_proxy in version 2.1 and earlier was affected by an open redirect vulnerability during the start and termination of the 2-legged OAuth flow. This issue was caused | Jul 17, 2017 | 6.1 | 19 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (13 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (13 CVEs).
Media Mentions
Signals from CVEs in this product scope (13 CVEs).
Top CNAs Publishing CVEs For Oauth2 Proxy
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.1 | 1 | 8.8 | 0.7% | 0 | 0 |