Vuln
·
Scope
Home
Packages
KEV
Critical
Insights
EN
中
Loading…
pkg:Bitnami/
oauth2-proxy
9 total CVEs
CRITICAL
3
HIGH
3
MEDIUM
2
LOW
1
✅ Check your installed version
Check
All known vulnerabilities
CRITICAL
9.1
CVE-2026-40575
OAuth2 Proxy has an Authentication Bypass via X-Forwarded-Uri Header Spoofing
>= 7.5.0, < 7.15.2
CRITICAL
9.1
CVE-2026-34457
OAuth2 Proxy: Health Check User-Agent Matching Bypasses Authentication in auth_request Mode
from 0, < 7.15.2
CRITICAL
9.1
CVE-2025-54576
OAuth2-Proxy has authentication bypass in oauth2-proxy skip_auth_routes due to Query Parameter inclusion
from 0, < 7.11.0
HIGH
8.5
OAuth2-Proxy vulnerable to header smuggling via underscore, leading to potential privilege escalation
from 0, < 7.13.0
HIGH
8.2
OAuth2 Proxy has an Authentication Bypass via Fragment Confusion in skip_auth_routes and skip_auth_regex
>= 7.5.0, < 7.15.2
HIGH
7.1
Open Redirect in OAuth2 Proxy
from 0, < 5.1.1
MEDIUM
6.8
OAuth2 Proxy has an Authorization Bypass in Email Domain Validation via Malformed Multi-@ Email Claims
from 0, < 7.15.2
MEDIUM
5.4
Subdomain checking of whitelisted domains could allow unintended redirects
from 0, < 7.0.0
LOW
3.5
OAuth2 Proxy: Session cookie not cleared when rendering sign-in page
>= 7.11.0, < 7.15.2
Bitnami/oauth2-proxy — 9 CVEs · VulnScope
CVE-2025-64484
CVE-2026-41059
CVE-2020-11053
CVE-2026-40574
CVE-2021-21291
CVE-2026-34454