Oauth2 Proxy Project
Oauth2 Proxy Project Oauth2 Proxy: vulnerabilidades y CVE
Oauth2 Proxy Project Oauth2 Proxy tiene 13 vulnerabilidades publicadas, 5 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE13
Últimos 12 meses5
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-41059 | Alta (8.2) | 0.43% | — | 22 abr 2026 | OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions 7.5.0 through 7.15.1 have a configuration-dependent authentication bypass. Deployments are affected when all of the following… |
| CVE-2026-40575 | Crítica (9.1) | 0.73% | — | 22 abr 2026 | OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions 7.5.0 through 7.15.1 may trust a client-supplied `X-Forwarded-Uri` header when `--reverse-proxy` is enabled and… |
| CVE-2026-40574 | Media (6.8) | 0.34% | — | 21 abr 2026 | OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Prior to 7.15.2, an authorization bypass exists in OAuth2 Proxy as part of the email_domain enforcement option. An attacker may be… |
| CVE-2026-34457 | Crítica (9.1) | 0.66% | — | 14 abr 2026 | OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions prior to 7.15.2 contain a configuration-dependent authentication bypass in deployments where OAuth2 Proxy is used with an… |
| CVE-2026-34454 | Baja (3.5) | 0.22% | — | 14 abr 2026 | OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. A regression introduced in 7.11.0 prevents OAuth2 Proxy from clearing the session cookie when rendering the sign-in page. In… |
| CVE-2025-54576 | Crítica (9.1) | 1.2% | — | 30 jul 2025 | OAuth2-Proxy is an open-source tool that can act as either a standalone reverse proxy or a middleware component integrated into existing reverse proxy or load balancer setups. In versions 7.10.0 and below, oauth2-proxy… |
| CVE-2021-21411 | Media (5.5) | 1.1% | — | 26 mar 2021 | OAuth2-Proxy is an open source reverse proxy that provides authentication with Google, Github or other providers. The `--gitlab-group` flag for group-based authorization in the GitLab provider stopped working in the… |
| CVE-2021-21291 | Media (6.1) | 1.6% | — | 2 feb 2021 | OAuth2 Proxy is an open-source reverse proxy and static file server that provides authentication using Providers (Google, GitHub, and others) to validate accounts by email, domain or group. In OAuth2 Proxy before… |
| CVE-2020-4037 | Media (5.4) | 0.90% | — | 29 jun 2020 | In OAuth2 Proxy from version 5.1.1 and less than version 6.0.0, users can provide a redirect address for the proxy to send the authenticated user to at the end of the authentication flow. This is expected to be the… |
| CVE-2020-11053 | Media (6.1) | 0.79% | — | 7 may 2020 | In OAuth2 Proxy before 5.1.1, there is an open redirect vulnerability. Users can provide a redirect address for the proxy to send the authenticated user to at the end of the authentication flow. This is expected to be… |
| CVE-2020-5233 | Media (6.1) | 1.3% | — | 30 ene 2020 | OAuth2 Proxy before 5.0 has an open redirect vulnerability. Authentication tokens could be silently harvested by an attacker. This has been patched in version 5.0. |
| CVE-2017-1000070 | Media (6.1) | 1.00% | — | 17 jul 2017 | The Bitly oauth2_proxy in version 2.1 and earlier was affected by an open redirect vulnerability during the start and termination of the 2-legged OAuth flow. This issue was caused by improper input validation and a… |
| CVE-2017-1000069 | Alta (8.8) | 0.74% | — | 17 jul 2017 | CSRF in Bitly oauth2_proxy 2.1 during authentication flow |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.