Uh oh!
There was an error while loading.Please reload this page.
- Notifications
You must be signed in to change notification settings - Fork2k
Security: oauth2-proxy/oauth2-proxy
Security
- Header smuggling via underscore leading to potential privilege escalationGHSA-vjrc-mh2v-45x6 published
Nov 8, 2025 bytuunitHigh - Authentication bypass in oauth2-proxy skip_auth_routes due to Query Parameter inclusionGHSA-7rh7-c77v-6434 published
Jul 30, 2025 bytuunitCritical - `--gitlab-group` GitLab Group Authorization config flag stopped working in v7.0.0GHSA-652x-m2gr-hppm published
Mar 25, 2021 byJoelSpeedModerate - Subdomain checking of whitelisted domains could allow unintended redirectsGHSA-4mf2-f3wh-gvf2 published
Feb 1, 2021 byJoelSpeedModerate - New OpenRedirect cases have been foundGHSA-5m6c-jp6f-2vcv published
Jun 27, 2020 byJoelSpeedHigh - Open Redirect Vulnerability with encoded Whitespace charactersGHSA-j7px-6hwj-hpjg published
May 6, 2020 byJoelSpeedHigh - The pattern '/\domain.com' is not disallowed when redirecting, allowing for open redirectGHSA-qqxw-m5fj-f7gv published
Jan 29, 2020 bystarkersHigh
Learn more about advisories related tooauth2-proxy/oauth2-proxy in theGitHub Advisory Database