github.com/oauth2-proxy/oauth2-proxy vulnerabilities
CVEs whose affected-version data names the github.com/oauth2-proxy/oauth2-proxy package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
3 CVEsRSS
CVE-2020-5233Medium· 5.9The pattern '/\domain.com' is not disallowed when redirecting, allowing for open redirect
The pattern '/\domain.com' is not disallowed when redirecting, allowing for open redirect
▾ Sunlitoauth2-proxy · github.com/oauth2-proxy/oauth2-proxyEPSS 1.3%via OSV
CVE-2020-4037Medium· 4.3Open Redirect in OAuth2 Proxy
Open Redirect in OAuth2 Proxy
▾ Sunlitoauth2-proxy · github.com/oauth2-proxy/oauth2-proxyEPSS 0.90%via OSV
CVE-2021-21291Medium· 5.4Subdomain checking of whitelisted domains could allow unintended redirects in oauth2-proxy
Subdomain checking of whitelisted domains could allow unintended redirects in oauth2-proxy
▾ Sunlitoauth2-proxy · github.com/oauth2-proxy/oauth2-proxy/v7EPSS 1.6%via OSV