Skip to content

oauth2-proxy

Reverse Proxies & Load Balancers

A flexible, open-source reverse proxy that adds OAuth2 / OIDC authentication to web applications

Go Latest v7.15.3 · 1mo ago Security brief →

Features

  • Acts as a standalone reverse proxy or middleware for existing proxies/load balancers
  • Supports many OAuth2 and OIDC providers, including Google, GitHub, and custom implementations
  • Extracts user details (username, groups) and forwards them as HTTP headers to upstream apps

Recent releases

View all 8 releases →
Upgrade now
v7.15.3 Breaking risk
Dependencies

Golang upgrade + dependency bumps + CVE fixes

v7.15.2 Security relevant patches GHSA-5hvv-m4w4-gf6v
Security fixes
  • CVE-2026-34986, CVE-2026-32281, CVE-2026-32289, CVE-2026-32288, CVE-2026-32280, CVE-2026-32282, CVE-2026-32283
  • GHSA-5hvv-m4w4-gf6v: Health check user-agent authentication bypass (Critical)
  • GHSA-7x63-xv5r-3p2x: X-Forwarded-Uri header spoofing authentication bypass (Critical)
Notable features
  • New --trusted-proxy-ip flag for explicit trusted reverse proxy IP configuration
v7.15.1 Bug fix

Fixed bugs in Unix socket handling for IP resolution, improved session refresh token logging, and corrected backend logout response handling.

v7.15.0 Breaking risk
Breaking changes
  • CSRF cookie validation now uses CSRFExpire instead of Expire
Notable features
  • OIDC JWT signing algorithm configuration
  • CSRF cookie SameSite option
  • Config validation flag
v7.14.3 Security relevant
Security fixes
  • CVE-2025-68121
Notable features
  • Redis URL parameter configuration

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

About

Stars
14,648
Forks
2,150
Languages
Go Makefile HTML

Install & Platforms

Install via
binary

Community & Support

Beta — feedback welcome: [email protected]