<titledata-react-helmet="true">Security | OAuth2 Proxy</title><metadata-react-helmet="true"name="twitter:card"content="summary_large_image"><metadata-react-helmet="true"property="og:url"content="https://oauth2-proxy.github.io/oauth2-proxy/docs/7.3.x/community/security"><metadata-react-helmet="true"name="docusaurus_locale"content="en"><metadata-react-helmet="true"name="docusaurus_version"content="7.3.x"><metadata-react-helmet="true"name="docusaurus_tag"content="docs-default-7.3.x"><metadata-react-helmet="true"property="og:title"content="Security | OAuth2 Proxy"><metadata-react-helmet="true"name="description"content="OAuth2 Proxy is a community project."><metadata-react-helmet="true"property="og:description"content="OAuth2 Proxy is a community project."><linkdata-react-helmet="true"rel="icon"href="/oauth2-proxy/img/logos/OAuth2_Proxy_icon.svg"><linkdata-react-helmet="true"rel="canonical"href="https://oauth2-proxy.github.io/oauth2-proxy/docs/7.3.x/community/security"><linkdata-react-helmet="true"rel="alternate"href="https://oauth2-proxy.github.io/oauth2-proxy/docs/7.3.x/community/security"hreflang="en"><linkdata-react-helmet="true"rel="alternate"href="https://oauth2-proxy.github.io/oauth2-proxy/docs/7.3.x/community/security"hreflang="x-default"><linkrel="stylesheet"href="/oauth2-proxy/assets/css/styles.19258e03.css">
<divrole="region"><ahref="#"class="skipToContent_ZgBM">Skip to main content</a></div><navclass="navbar navbar--fixed-top"><divclass="navbar__inner"><divclass="navbar__items"><buttonaria-label="Navigation bar toggle"class="navbar__toggle clean-btn"type="button"tabindex="0"><svgwidth="30"height="30"viewBox="0 0 30 30"aria-hidden="true"><pathstroke="currentColor"stroke-linecap="round"stroke-miterlimit="10"stroke-width="2"d="M4 7h22M4 15h22M4 23h22"></path></svg></button><aclass="navbar__brand"href="/oauth2-proxy/"><divclass="navbar__logo"><imgsrc="/oauth2-proxy/img/logos/OAuth2_Proxy_icon.svg"alt="OAuth2 Proxy"class="themedImage_W2Cr themedImage--light_TfLj"><imgsrc="/oauth2-proxy/img/logos/OAuth2_Proxy_icon.svg"alt="OAuth2 Proxy"class="themedImage_W2Cr themedImage--dark_oUvU"></div><bclass="navbar__title">OAuth2 Proxy</b></a><aaria-current="page"class="navbar__item navbar__link navbar__link--active"href="/oauth2-proxy/docs/">Docs</a></div><divclass="navbar__items navbar__items--right"><divclass="navbar__item dropdown dropdown--hoverable dropdown--right"><aclass="navbar__link"href="/oauth2-proxy/docs/7.3.x/">7.3.x</a><ulclass="dropdown__menu"><li><aclass="dropdown__link"href="/oauth2-proxy/docs/next/community/security">Next</a></li><li><aclass="dropdown__link"href="/oauth2-proxy/docs/community/security">7.4.x</a></li><li><aaria-current="page"class="dropdown__link dropdown__link--active"href="/oauth2-proxy/docs/7.3.x/community/security">7.3.x</a></li><li><aclass="dropdown__link"href="/oauth2-proxy/docs/7.2.x/community/security">7.2.x</a></li><li><aclass="dropdown__link"href="/oauth2-proxy/docs/7.1.x/community/security">7.1.x</a></li><li><aclass="dropdown__link"href="/oauth2-proxy/docs/7.0.x/community/security">7.0.x</a></li><li><aclass="dropdown__link"href="/oauth2-proxy/docs/6.1.x/community/security">6.1.x</a></li></ul></div><ahref="https://github.com/oauth2-proxy/oauth2-proxy"target="_blank"rel="noopener noreferrer"class="navbar__item navbar__link"><span>GitHub<svgwidth="13.5"height="13.5"aria-hidden="true"viewBox="0 0 24 24"class="iconExternalLink_I5OW"><pathfill="currentColor"d="M21 13v10h-21v-19h12v2h-10v15h17v-8h2zm3-12h-10.988l4.035 4-6.977 7.07 2.828 2.828 6.977-7.07 4.125 4.172v-11z"></path></svg></span></a><divclass="toggle_Pssr toggle_TdHA toggleDisabled_jDku"><divclass="toggleTrack_SSoT"role="button"tabindex="-1"><divclass="toggleTrackCheck_XobZ"><spanclass="toggleIcon_eZtF">🌜</span></div><divclass="toggleTrackX_YkSC"><spanclass="toggleIcon_eZtF">🌞</span></div><divclass="toggleTrackThumb_uRm4"></div></div><inputtype="checkbox"class="toggleScreenReader_JnkT"aria-label="Switch between dark and light mode"></div></div></div><divrole="presentation"class="navbar-sidebar__backdrop"></div></nav><divclass="main-wrapper docs-wrapper docs-doc-page"><divclass="docPage_P2Lg"><buttonaria-label="Scroll back to top"class="clean-btn theme-back-to-top-button backToTopButton_RiI4"type="button"></button><asideclass="theme-doc-sidebar-container docSidebarContainer_rKC_"><divclass="sidebar_CW9Y"><navclass="menu thin-scrollbar menu_SkdO"><ulclass="theme-doc-sidebar-menu menu__list"><liclass="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-1 menu__list-item"><aclass="menu__link"href="/oauth2-proxy/docs/7.3.x/">Installation</a></li><liclass="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-1 menu__list-item"><aclass="menu__link"href="/oauth2-proxy/docs/7.3.x/behaviour">Behaviour</a></li><liclass="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-1 menu__list-item"><divclass="menu__list-item-collapsible"><aclass="menu__link menu__link--sublist hasHref_VCh3"href="/oauth2-proxy/docs/7.3.x/configuration/overview">Configuration</a></div><ulstyle="display:block;overflow:visible;height:auto"class="menu__list"><liclass="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-2 menu__list-item"><aclass="menu__link"tabindex="0"href="/oauth2-proxy/docs/7.3.x/configuration/overview">Overvi
Maintainers do not work on this project full time, and as such,
while we endeavour to respond to disclosures as quickly as possible,
this may take longer than in projects with corporate sponsorship.</p></div></div><h2class="anchor anchorWithStickyNavbar_mojV"id="security-disclosures">Security Disclosures<aclass="hash-link"href="#security-disclosures"title="Direct link to heading"></a></h2><divclass="admonition admonition-important alert alert--info"><divclass="admonition-heading"><h5><spanclass="admonition-icon"><svgxmlns="http://www.w3.org/2000/svg"width="14"height="16"viewBox="0 0 14 16"><pathfill-rule="evenodd"d="M7 2.3c3.14 0 5.7 2.56 5.7 5.7s-2.56 5.7-5.7 5.7A5.71 5.71 0 0 1 1.3 8c0-3.14 2.56-5.7 5.7-5.7zM7 1C3.14 1 0 4.14 0 8s3.14 7 7 7 7-3.14 7-7-3.14-7-7-7zm1 3H6v5h2V4zm0 6H6v2h2v-2z"></path></svg></span>important</h5></div><divclass="admonition-content"><p>If you believe you have found a vulnerability within OAuth2 Proxy or any of its
dependencies, please do NOT open an issue or PR on GitHub, please do NOT post
any details publicly.</p></div></div><p>Security disclosures MUST be done in private.
If you have found an issue that you would like to bring to the attention of the
maintenance team for OAuth2 Proxy, please compose an email and send it to the
list of maintainers in our <ahref="https://github.com/oauth2-proxy/oauth2-proxy/blob/master/MAINTAINERS"target="_blank"rel="noopener noreferrer">MAINTAINERS</a> file.</p><p>Please include as much detail as possible.
Ideally, your disclosure should include:</p><ul><li>A reproducible case that can be used to demonstrate the exploit</li><li>How you discovered this vulnerability</li><li>A potential fix for the issue (if you have thought of one)</li><li>Versions affected (if not present in master)</li><li>Your GitHub ID</li></ul><h3class="anchor anchorWithStickyNavbar_mojV"id="how-will-we-respond-to-disclosures">How will we respond to disclosures?<aclass="hash-link"href="#how-will-we-respond-to-disclosures"title="Direct link to heading"></a></h3><p>We use <ahref="https://docs.github.com/en/github/managing-security-vulnerabilities/about-github-security-advisories"target="_blank"rel="noopener noreferrer">GitHub Security Advisories</a>
to privately discuss fixes for disclosed vulnerabilities.
If you include a GitHub ID with your disclosure we will add you as a collaborator
for the advisory so that you can join the discussion and validate any fixes
we may propose.</p><p>For minor issues and previously disclosed vulnerabilities (typically for
dependencies), we may use regular PRs for fixes and forego the security advisory.</p><p>Once a fix has been agreed upon, we will merge the fix and create a new release.
If we have multiple security issues in flight simultaneously, we may delay
merging fixes until all patches are ready.
We may also backport the fix to previous releases,