VendorsOAuth2 Proxy Projectoauth2_proxyany version
Vulnerabilities

OAuth2 Proxy Project oauth2 proxy any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

12CVEs
CVE-2025-54576
OAuth2-Proxy has authentication bypass in oauth2-proxy skip_auth_routes due to Query Parameter inclusion
Published 2025-07-30 · Analyzed
9.1EPSS 0.012
CVE-2026-40575
OAuth2 Proxy has an Authentication Bypass via X-Forwarded-Uri Header Spoofing
Published 2026-04-21 · Modified
9.1EPSS 0.007
CVE-2026-34457
OAuth2 Proxy: Health Check User-Agent Matching Bypasses Authentication in auth_request Mode
Published 2026-04-14 · Analyzed
9.1EPSS 0.007
CVE-2026-41059
OAuth2 Proxy has an Authentication Bypass via Fragment Confusion in skip_auth_routes and skip_auth_regex
Published 2026-04-21 · Analyzed
8.2EPSS 0.004
CVE-2020-11053
Open Redirect in OAuth2 Proxy
Published 2020-05-07 · Modified
7.1EPSS 0.008
CVE-2026-40574
OAuth2 Proxy has an Authorization Bypass in Email Domain Validation via Malformed Multi-@ Email Claims
Published 2026-04-21 · Analyzed
6.8EPSS 0.003
CVE-2021-21291
Subdomain checking of whitelisted domains could allow unintended redirects
Published 2021-02-02 · Modified
6.1EPSS 0.016
CVE-2020-5233
Open Redirect in OAuth2 Proxy
Published 2020-01-30 · Modified
6.1EPSS 0.013
CVE-2017-1000070
The Bitly oauth2_proxy in version 2.1 and earlier was affected by an open redirect vulnerability during the start and termination of the 2-legged OAuth flow. This issue was caused by improper input validation and a violation of RFC-6819
Published 2017-07-13 · Modified
6.1EPSS 0.010
CVE-2020-4037
Open Redirect in OAuth2 Proxy
Published 2020-06-29 · Modified
5.8EPSS 0.009
CVE-2021-21411
Incorrect authorization in OAuth2-Proxy
Published 2021-03-26 · Modified
5.5EPSS 0.010
CVE-2026-34454
OAuth2 Proxy: Session cookie not cleared when rendering sign-in page
Published 2026-04-14 · Analyzed
3.5EPSS 0.002