Download Latest Version v7.15.5 source code.zip (2.3 MB) Google Add to Preferred Sources
Home / v7.15.5
Name Modified Size InfoDownloads / Week
Parent folder
oauth2-proxy-v7.15.5.linux-armv6.tar.gz-sha256sum.txt 2026-10-01 106 Bytes
oauth2-proxy-v7.15.5.linux-armv7-sha256sum.txt 2026-10-01 112 Bytes
oauth2-proxy-v7.15.5.linux-armv7.tar.gz-sha256sum.txt 2026-10-01 106 Bytes
oauth2-proxy-v7.15.5.linux-ppc64le-sha256sum.txt 2026-10-01 114 Bytes
oauth2-proxy-v7.15.5.linux-ppc64le.tar.gz-sha256sum.txt 2026-10-01 108 Bytes
oauth2-proxy-v7.15.5.linux-s390x-sha256sum.txt 2026-10-01 112 Bytes
oauth2-proxy-v7.15.5.linux-s390x.tar.gz-sha256sum.txt 2026-10-01 106 Bytes
oauth2-proxy-v7.15.5.windows-amd64-sha256sum.txt 2026-10-01 118 Bytes
oauth2-proxy-v7.15.5.windows-amd64.tar.gz-sha256sum.txt 2026-10-01 108 Bytes
oauth2-proxy-v7.15.5.freebsd-amd64.tar.gz-sha256sum.txt 2026-10-01 108 Bytes
oauth2-proxy-v7.15.5.linux-amd64-sha256sum.txt 2026-10-01 112 Bytes
oauth2-proxy-v7.15.5.linux-amd64.tar.gz-sha256sum.txt 2026-10-01 106 Bytes
oauth2-proxy-v7.15.5.linux-arm64-sha256sum.txt 2026-10-01 112 Bytes
oauth2-proxy-v7.15.5.linux-arm64.tar.gz-sha256sum.txt 2026-10-01 106 Bytes
oauth2-proxy-v7.15.5.linux-armv5-sha256sum.txt 2026-10-01 112 Bytes
oauth2-proxy-v7.15.5.linux-armv5.tar.gz-sha256sum.txt 2026-10-01 106 Bytes
oauth2-proxy-v7.15.5.linux-armv6-sha256sum.txt 2026-10-01 112 Bytes
oauth2-proxy-v7.15.5.darwin-amd64-sha256sum.txt 2026-10-01 113 Bytes
oauth2-proxy-v7.15.5.darwin-amd64.tar.gz-sha256sum.txt 2026-10-01 107 Bytes
oauth2-proxy-v7.15.5.darwin-arm64-sha256sum.txt 2026-10-01 113 Bytes
oauth2-proxy-v7.15.5.darwin-arm64.tar.gz-sha256sum.txt 2026-10-01 107 Bytes
oauth2-proxy-v7.15.5.freebsd-amd64-sha256sum.txt 2026-10-01 114 Bytes
oauth2-proxy-v7.15.5.windows-amd64.tar.gz 2026-10-01 20.1 MB
oauth2-proxy-v7.15.5.linux-armv7.tar.gz 2026-10-01 18.1 MB
oauth2-proxy-v7.15.5.linux-ppc64le.tar.gz 2026-10-01 18.5 MB
oauth2-proxy-v7.15.5.linux-s390x.tar.gz 2026-10-01 19.9 MB
oauth2-proxy-v7.15.5.linux-armv5.tar.gz 2026-10-01 18.1 MB
oauth2-proxy-v7.15.5.linux-armv6.tar.gz 2026-10-01 18.1 MB
oauth2-proxy-v7.15.5.darwin-amd64.tar.gz 2026-10-01 20.9 MB
oauth2-proxy-v7.15.5.darwin-arm64.tar.gz 2026-10-01 19.6 MB
oauth2-proxy-v7.15.5.freebsd-amd64.tar.gz 2026-10-01 19.8 MB
oauth2-proxy-v7.15.5.linux-amd64.tar.gz 2026-10-01 19.9 MB
oauth2-proxy-v7.15.5.linux-arm64.tar.gz 2026-10-01 18.2 MB
README.md 2026-10-01 5.8 kB
v7.15.5 source code.tar.gz 2026-10-01 1.9 MB
v7.15.5 source code.zip 2026-10-01 2.3 MB
Totals: 36 Items   215.4 MB 2

Release Highlights

Important Notes

The Bitbucket provider --bitbucket-team flag got deprecated and we added --bitbucket-workspace flag to restrict logins to members of a specific workspace instead of a team. The --bitbucket-team flag is still supported and will act like workspace but will be removed in a future release. Please update your configuration to use the new --bitbucket-workspace flag. For more information, refer to Bitbucket teams API deprecation.

Additionally refer to OAuth client configuration for Bitbucket provider in the documentation. for changes in the scopes (Account>Read) is now required if you restrict by workspace.

Security Advisories:

  • (Critical) GHSA-63jm-59jj-478j Authentication bypass via inconsistent skip-auth path interpretation
  • (Critical) GHSA-wr5q-7wxw-x568 Authentication bypass via spoofed client-IP headers in OAuth2 Proxy
  • (Moderate) GHSA-hhqp-vx7f-5c6m Credential disclosure through OAuth callback error logging

Read more below

Critical Fixes

For a small subset of deployments these fixes might be breaking change for the sake of fixing trust/security boundaries.

GHSA-63jm-59jj-478j Authentication bypass via inconsistent skip-auth path interpretation

Skip-auth path matching is now stricter: --skip-auth-route and --skip-auth-regex no longer grant exemptions for invalid or ambiguous paths, even when a positive or negated rule would otherwise match. This includes dot segments, repeated slashes (including leading //), semicolons, backslashes, fragment-like content, decoded question marks, and control characters, including encoded forms. For example, previously public /public/file;version=1 and /public//file now follow normal authentication and authorization. # and %23 are no longer silently stripped before matching.

Trusted X-Forwarded-Uri metadata must use origin form (/path?query), not a full URL. Before upgrading, review public-route exemptions and external-auth header configuration. If unusual paths must remain public, expose them separately from the protected routing boundary rather than broadening skip-auth rules.

Flag names and configuration syntax are unchanged. Ordinary query strings, trailing-slash distinctions, and unambiguous escaped characters retain their matching behavior. The fix does not rewrite upstream request targets or unconditionally reject authenticated requests; existing router behavior and separately configured exemptions remain unchanged.

GHSA-wr5q-7wxw-x568 Authentication bypass via spoofed client-IP headers in OAuth2 Proxy

Trusted client-IP resolution now enforces trusted proxy boundaries: When --reverse-proxy is enabled, client-IP headers configured via --real-client-ip-header are accepted only from direct peers that match --trusted-proxy-ip. If the direct peer is not trusted, the transport peer address is evaluated instead.

For X-Forwarded-For, the chain is traversed from right to left, skipping intermediate proxies in --trusted-proxy-ip and treating the first untrusted address as the client. Leftmost entries cannot be spoofed past the trusted proxy boundary. If --trusted-proxy-ip is left unset, OAuth2 Proxy preserves backwards compatibility by trusting all source addresses and retaining the leftmost behavior, which does not protect against spoofed XFF headers. To secure --trusted-ip exemptions behind a reverse proxy, configure explicit, narrowly scoped --trusted-proxy-ip CIDR ranges and ensure the proxy sanitizes client-IP headers. Missing or malformed client-IP headers from a trusted proxy will no longer fall back to granting exemptions based on the proxy's own IP.

Breaking Changes

Changes since v7.15.4

  • #3546 fix: strip the port from the request host when matching cookie domains @kirilju
  • #3547 fix: refresh additional claims for OIDC and MS Entra ID providers and properly populate additional claims during login (@Apollo3zehn)
  • #3477 fix(bitbucket): auth failure due to Bitbucket OAuth 2.0 changes on May 4th 2026 @mfouad
  • #3535 fix: surface Microsoft Graph errors during Entra group overage instead of logging in with an incomplete group set @no-hup
  • #3527 fix(encryption): return an error instead of panicking on a short GCM ciphertext @winklemad
Source: README.md, updated 2026-10-01