github.com/oauth2-proxy/oauth2-proxy/v7 vulnerabilities
CVEs whose affected-version data names the github.com/oauth2-proxy/oauth2-proxy/v7 package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
4 CVEsRSS
CVE-2026-40574Medium· 6.8OAuth2 Proxy has an Authorization Bypass in Email Domain Validation via Malformed Multi-@ Email Claims
OAuth2 Proxy has an Authorization Bypass in Email Domain Validation via Malformed Multi-@ Email Claims
▾ Sunlitoauth2-proxy · github.com/oauth2-proxy/oauth2-proxy/v7EPSS 0.21%via OSV
CVE-2025-54576Critical· 9.1OAuth2-Proxy has authentication bypass in oauth2-proxy skip_auth_routes due to Query Parameter inclusion
OAuth2-Proxy has authentication bypass in oauth2-proxy skip_auth_routes due to Query Parameter inclusion
▾ Midnightoauth2-proxy · github.com/oauth2-proxy/oauth2-proxy/v7EPSS 1.2%via OSV
CVE-2021-21411Medium· 5.5OAuth2-Proxy's `--gitlab-group` GitLab Group Authorization config flag stopped working in v7.0.0
OAuth2-Proxy's `--gitlab-group` GitLab Group Authorization config flag stopped working in v7.0.0
▾ Sunlitoauth2-proxy · github.com/oauth2-proxy/oauth2-proxy/v7EPSS 0.99%via OSV
CVE-2021-21291Medium· 5.4Subdomain checking of whitelisted domains could allow unintended redirects in oauth2-proxy
Subdomain checking of whitelisted domains could allow unintended redirects in oauth2-proxy
▾ Sunlitoauth2-proxy · github.com/oauth2-proxy/oauth2-proxy/v7EPSS 1.6%via OSV