Release Highlights
- 🔵 Golang version upgrade to v1.26.8
- Upgrade of all dependencies to their latest versions
- 🕵️♀️ Vulnerabilities have been addressed
Important Notes
The Bitbucket provider --bitbucket-team flag got deprecated and we added --bitbucket-workspace flag to restrict logins to members of a specific workspace instead of a team. The --bitbucket-team flag is still supported and will act like workspace but will be removed in a future release. Please update your configuration to use the new --bitbucket-workspace flag. For more information, refer to Bitbucket teams API deprecation.
Additionally refer to OAuth client configuration for Bitbucket provider in the documentation. for changes in the scopes (Account>Read) is now required if you restrict by workspace.
Security Advisories:
- (Critical) GHSA-63jm-59jj-478j Authentication bypass via inconsistent skip-auth path interpretation
- (Critical) GHSA-wr5q-7wxw-x568 Authentication bypass via spoofed client-IP headers in OAuth2 Proxy
- (Moderate) GHSA-hhqp-vx7f-5c6m Credential disclosure through OAuth callback error logging
Read more below
Critical Fixes
For a small subset of deployments these fixes might be breaking change for the sake of fixing trust/security boundaries.
GHSA-63jm-59jj-478j Authentication bypass via inconsistent skip-auth path interpretation
Skip-auth path matching is now stricter: --skip-auth-route and
--skip-auth-regex no longer grant exemptions for invalid or ambiguous paths,
even when a positive or negated rule would otherwise match. This includes dot
segments, repeated slashes (including leading //), semicolons, backslashes,
fragment-like content, decoded question marks, and control characters, including
encoded forms. For example, previously public /public/file;version=1 and
/public//file now follow normal authentication and authorization. # and %23
are no longer silently stripped before matching.
Trusted X-Forwarded-Uri metadata must use origin form (/path?query), not a full
URL. Before upgrading, review public-route exemptions and external-auth header
configuration. If unusual paths must remain public, expose them separately from
the protected routing boundary rather than broadening skip-auth rules.
Flag names and configuration syntax are unchanged. Ordinary query strings, trailing-slash distinctions, and unambiguous escaped characters retain their matching behavior. The fix does not rewrite upstream request targets or unconditionally reject authenticated requests; existing router behavior and separately configured exemptions remain unchanged.
GHSA-wr5q-7wxw-x568 Authentication bypass via spoofed client-IP headers in OAuth2 Proxy
Trusted client-IP resolution now enforces trusted proxy boundaries: When
--reverse-proxy is enabled, client-IP headers configured via
--real-client-ip-header are accepted only from direct peers that match
--trusted-proxy-ip. If the direct peer is not trusted, the transport peer
address is evaluated instead.
For X-Forwarded-For, the chain is traversed from right to left, skipping
intermediate proxies in --trusted-proxy-ip and treating the first untrusted
address as the client. Leftmost entries cannot be spoofed past the trusted proxy
boundary. If --trusted-proxy-ip is left unset, OAuth2 Proxy preserves backwards
compatibility by trusting all source addresses and retaining the leftmost
behavior, which does not protect against spoofed XFF headers. To secure
--trusted-ip exemptions behind a reverse proxy, configure explicit, narrowly
scoped --trusted-proxy-ip CIDR ranges and ensure the proxy sanitizes client-IP
headers. Missing or malformed client-IP headers from a trusted proxy will no
longer fall back to granting exemptions based on the proxy's own IP.
Breaking Changes
Changes since v7.15.4
- #3546 fix: strip the port from the request host when matching cookie domains @kirilju
- #3547 fix: refresh additional claims for OIDC and MS Entra ID providers and properly populate additional claims during login (@Apollo3zehn)
- #3477 fix(bitbucket): auth failure due to Bitbucket OAuth 2.0 changes on May 4th 2026 @mfouad
- #3535 fix: surface Microsoft Graph errors during Entra group overage instead of logging in with an incomplete group set @no-hup
- #3527 fix(encryption): return an error instead of panicking on a short GCM ciphertext @winklemad