oauth2-proxy
Reverse Proxies & Load BalancersA flexible, open-source reverse proxy that adds OAuth2 / OIDC authentication to web applications
Features
- Acts as a standalone reverse proxy or middleware for existing proxies/load balancers
- Supports many OAuth2 and OIDC providers, including Google, GitHub, and custom implementations
- Extracts user details (username, groups) and forwards them as HTTP headers to upstream apps
Recent releases
View all 8 releases →
v7.15.2
Security relevant
patches GHSA-5hvv-m4w4-gf6v
Security fixes
- CVE-2026-34986, CVE-2026-32281, CVE-2026-32289, CVE-2026-32288, CVE-2026-32280, CVE-2026-32282, CVE-2026-32283
- GHSA-5hvv-m4w4-gf6v: Health check user-agent authentication bypass (Critical)
- GHSA-7x63-xv5r-3p2x: X-Forwarded-Uri header spoofing authentication bypass (Critical)
Notable features
- New --trusted-proxy-ip flag for explicit trusted reverse proxy IP configuration
v7.15.1
Bug fix
Fixed bugs in Unix socket handling for IP resolution, improved session refresh token logging, and corrected backend logout response handling.
v7.15.0
Breaking risk
Breaking changes
- CSRF cookie validation now uses CSRFExpire instead of Expire
Notable features
- OIDC JWT signing algorithm configuration
- CSRF cookie SameSite option
- Config validation flag
v7.14.3
Security relevant
Security fixes
- CVE-2025-68121
Notable features
- Redis URL parameter configuration
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Install & Platforms
Install via
binary