Skip to content
release
BETA
Releases
Tools
Vendors
Trending
$refs.securityHub.focus())"
:aria-expanded="open"
aria-haspopup="menu"
class="inline-flex items-center gap-1 px-3 py-1.5 rounded text-[13px] font-medium transition-colors text-[var(--text-secondary)] dark:text-[var(--text-muted)] hover:text-[var(--text-primary)] dark:hover:text-[var(--text-primary)] hover:bg-[var(--surface-hover)] dark:hover:bg-[var(--surface-elevated)]"
>
Security
Tools
/
oauth2-proxy
OA
oauth2-proxy
Reverse Proxies & Load Balancers
A flexible, open‑source reverse proxy that adds OAuth2 / OIDC authentication to web applications
Go
·
Latest v7.15.2 · 1mo ago
Security brief →
Features
Acts as a standalone reverse proxy or middleware component
Supports generic OAuth2 and OIDC providers plus specialized implementations (Google, GitHub, etc.)
Extracts user details (username, groups) and forwards them as HTTP headers
v7.15.2
Security relevant
patches GHSA-5hvv-m4w4-gf6v
·
1mo
Security fixes
CVE-2026-34986, CVE-2026-32281, CVE-2026-32289, CVE-2026-32288, CVE-2026-32280, CVE-2026-32282, CVE-2026-32283 GHSA-5hvv-m4w4-gf6v: Health check user-agent authentication bypass (Critical) GHSA-7x63-xv5r-3p2x: X-Forwarded-Uri header spoofing authentication bypass (Critical)
Notable features
New --trusted-proxy-ip flag for explicit trusted reverse proxy IP configuration
v7.15.1
Bug fix
·
2mo
Fixed bugs in Unix socket handling for IP resolution, improved session refresh token logging, and corrected backend logout response handling.
v7.15.0
Breaking risk
·
2mo
Breaking changes
CSRF cookie validation now uses CSRFExpire instead of Expire
Notable features
OIDC JWT signing algorithm configuration CSRF cookie SameSite option Config validation flag
v7.14.3
Security relevant
·
3mo
Notable features
Redis URL parameter configuration
v7.14.2
Bug fix
·
4mo
Reverted AuthOnly endpoint change that incorrectly returned 302 redirects, restoring 401 status when no session exists. Documentation improved for nginx auth_request configuration.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Releases per month
Releases per month, last 12 months.
Cadence
0.2 / wk
Last release
50d
Tracked
7
Security score
4.9/10
OpenSSF
4.2/10
Open CVEs
0
SBOM
SECURITY.md
Active maintainer
Community
GitHub stars
14,476
Forks
2,137
Open issues
223
Open PRs
69
Stars/wk velocity
0.0
HN peak
2
About
Languages
Go
·
Makefile
·
HTML
View on GitHub
Homepage
Documentation
{ copied = true; setTimeout(() => copied = false, 2000) })"
class="flex items-center gap-1.5 text-[12px] text-[var(--text-muted)] dark:text-[var(--text-muted)] hover:text-[var(--accent)] dark:hover:text-[var(--accent)] transition-colors"
>
About
Languages
Go
·
Makefile
·
HTML
View on GitHub
Homepage
Documentation
{ copied = true; setTimeout(() => copied = false, 2000) })"
class="flex items-center gap-1.5 text-[12px] text-[var(--text-muted)] dark:text-[var(--text-muted)] hover:text-[var(--accent)] dark:hover:text-[var(--accent)] transition-colors"
>
© 2026 releaseport. All rights reserved.
Feed
Tools
Feeds
Security
Brief
Search tools, categories, lists, and users
Use ↑↓ to navigate, Enter to open, Esc to close
No results for " "
⌘K to open
↑↓ navigate
⏎ open