« Volver al listado

Oauth2 Proxy Project

Oauth2 Proxy Project Oauth2 Proxy: vulnerabilidades y CVE

Oauth2 Proxy Project Oauth2 Proxy tiene 13 vulnerabilidades publicadas, 5 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE13
Últimos 12 meses5
Críticas3
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-41059Alta (8.2)0.43%—22 abr 2026
OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions 7.5.0 through 7.15.1 have a configuration-dependent authentication bypass. Deployments are affected when all of the following…
CVE-2026-40575Crítica (9.1)0.73%—22 abr 2026
OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions 7.5.0 through 7.15.1 may trust a client-supplied `X-Forwarded-Uri` header when `--reverse-proxy` is enabled and…
CVE-2026-40574Media (6.8)0.34%—21 abr 2026
OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Prior to 7.15.2, an authorization bypass exists in OAuth2 Proxy as part of the email_domain enforcement option. An attacker may be…
CVE-2026-34457Crítica (9.1)0.66%—14 abr 2026
OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions prior to 7.15.2 contain a configuration-dependent authentication bypass in deployments where OAuth2 Proxy is used with an…
CVE-2026-34454Baja (3.5)0.22%—14 abr 2026
OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. A regression introduced in 7.11.0 prevents OAuth2 Proxy from clearing the session cookie when rendering the sign-in page. In…
CVE-2025-54576Crítica (9.1)1.2%—30 jul 2025
OAuth2-Proxy is an open-source tool that can act as either a standalone reverse proxy or a middleware component integrated into existing reverse proxy or load balancer setups. In versions 7.10.0 and below, oauth2-proxy…
CVE-2021-21411Media (5.5)1.1%—26 mar 2021
OAuth2-Proxy is an open source reverse proxy that provides authentication with Google, Github or other providers. The `--gitlab-group` flag for group-based authorization in the GitLab provider stopped working in the…
CVE-2021-21291Media (6.1)1.6%—2 feb 2021
OAuth2 Proxy is an open-source reverse proxy and static file server that provides authentication using Providers (Google, GitHub, and others) to validate accounts by email, domain or group. In OAuth2 Proxy before…
CVE-2020-4037Media (5.4)0.90%—29 jun 2020
In OAuth2 Proxy from version 5.1.1 and less than version 6.0.0, users can provide a redirect address for the proxy to send the authenticated user to at the end of the authentication flow. This is expected to be the…
CVE-2020-11053Media (6.1)0.79%—7 may 2020
In OAuth2 Proxy before 5.1.1, there is an open redirect vulnerability. Users can provide a redirect address for the proxy to send the authenticated user to at the end of the authentication flow. This is expected to be…
CVE-2020-5233Media (6.1)1.3%—30 ene 2020
OAuth2 Proxy before 5.0 has an open redirect vulnerability. Authentication tokens could be silently harvested by an attacker. This has been patched in version 5.0.
CVE-2017-1000070Media (6.1)1.00%—17 jul 2017
The Bitly oauth2_proxy in version 2.1 and earlier was affected by an open redirect vulnerability during the start and termination of the 2-legged OAuth flow. This issue was caused by improper input validation and a…
CVE-2017-1000069Alta (8.8)0.74%—17 jul 2017
CSRF in Bitly oauth2_proxy 2.1 during authentication flow

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1078 Valid Accounts4
  2. T1190 Exploit Public-Facing Application4

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.