VulnSea

oauth2-proxy has 6 CVEs on record between 2021 and 2026. The median CVSS is 5.7 (medium), with 1 rated critical. None have a confirmed exploitation report. Most affected products: github.com/oauth2-proxy/oauth2-proxy/v7 (4), github.com/oauth2-proxy/oauth2-proxy (2).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
5.7
Publish → KEV
Last 90 days
0 prev 1

Products

  • github.com/oauth2-proxy/oauth2-proxy/v7 4
  • github.com/oauth2-proxy/oauth2-proxy 2
6
Total CVEs
1
Critical
0
CISA KEV
0
Exploited

oauth2-proxy vulnerabilities

CVEs affecting oauth2-proxy, newest first. Open any entry for full detail, references, and exploit status.

6 CVEsRSS

CVE-2026-40574Medium· 6.8
5mo ago

OAuth2 Proxy has an Authorization Bypass in Email Domain Validation via Malformed Multi-@ Email Claims

OAuth2 Proxy has an Authorization Bypass in Email Domain Validation via Malformed Multi-@ Email Claims

Sunlitoauth2-proxy · github.com/oauth2-proxy/oauth2-proxy/v7EPSS 0.21%via OSV
CVE-2025-54576Critical· 9.1
1y ago

OAuth2-Proxy has authentication bypass in oauth2-proxy skip_auth_routes due to Query Parameter inclusion

OAuth2-Proxy has authentication bypass in oauth2-proxy skip_auth_routes due to Query Parameter inclusion

Midnightoauth2-proxy · github.com/oauth2-proxy/oauth2-proxy/v7EPSS 1.2%via OSV
CVE-2021-21411Medium· 5.5
1y ago

OAuth2-Proxy's `--gitlab-group` GitLab Group Authorization config flag stopped working in v7.0.0

OAuth2-Proxy's `--gitlab-group` GitLab Group Authorization config flag stopped working in v7.0.0

Sunlitoauth2-proxy · github.com/oauth2-proxy/oauth2-proxy/v7EPSS 0.99%via OSV
CVE-2020-5233Medium· 5.9
4y ago

The pattern '/\domain.com' is not disallowed when redirecting, allowing for open redirect

The pattern '/\domain.com' is not disallowed when redirecting, allowing for open redirect

Sunlitoauth2-proxy · github.com/oauth2-proxy/oauth2-proxyEPSS 1.3%via OSV
CVE-2020-4037Medium· 4.3
4y ago

Open Redirect in OAuth2 Proxy

Open Redirect in OAuth2 Proxy

Sunlitoauth2-proxy · github.com/oauth2-proxy/oauth2-proxyEPSS 0.90%via OSV
CVE-2021-21291Medium· 5.4
5y ago

Subdomain checking of whitelisted domains could allow unintended redirects in oauth2-proxy

Subdomain checking of whitelisted domains could allow unintended redirects in oauth2-proxy

Sunlitoauth2-proxy · github.com/oauth2-proxy/oauth2-proxy/v7EPSS 1.6%via OSV
oauth2-proxy vulnerabilities (CVEs) · VulnSea