oauth2-proxy Helm chart
presto-loadbalancerScored 14 Sept 2026
A reverse proxy that provides authentication with Google, Github or other providers
Latest 4.3.18 2 years agodeploys tag 1.15.9-alpine 0Artifact Hub
oauth2-proxy 4.3.18 deploys 2 container images: library/nginx and quay.io/oauth2-proxy/oauth2-proxy. Across them, 260 findings — 3 critical, 11 high — 2 on CISA KEV. The highest contribution is ALPINE-CVE-2020-15999 in freetype 2.9.1-r2, fixed in 2.9.1-r3. Chart.yaml declares kubeVersion >=1.9.0-0; rendered for Kubernetes 1.9.0.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Container images
| Image | Tag | Vulnerabilities | Radar Score |
|---|---|---|---|
| library/ | 1.15.9-alpine | 23235 | 951 |
| quay.io/ | v6.1.1 | 1844174 | 3,007 |
Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.
Vulnerabilities
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Critical | ALPINE-CVE-2020-15999KEV | freetype | 2.9.1-r3 |
| Critical | ALPINE-CVE-2021-3711 | openssl | 1.1.1l-r0 |
| Critical | ALPINE-CVE-2019-6977 | gd | 2.2.5-r2 |
| High | ALPINE-CVE-2021-23840 | openssl | 1.1.1j-r0 |
| High | ALPINE-CVE-2021-3712 | openssl | 1.1.1l-r0 |
| High | GHSA-45x7-px36-x8w8 | golang.org/ | 0.0.0-20231218163308-9d2ee975ef9f |
| High | ALPINE-CVE-2022-37434 | zlib | 1.2.11-r4 |
| High | GHSA-qppj-fm5r-hxr3KEV | golang.org/ | 0.17.0 |
| High | GHSA-4v7x-pqxf-cx7m | golang.org/ | 0.23.0 |
| High | ALPINE-CVE-2021-3449 | openssl | 1.1.1k-r0 |
| High | GHSA-ffhg-7mh4-33c4 | golang.org/ | 0.0.0-20200220183623-bac4c82f6975 |
| High | ALPINE-CVE-2019-12900 | bzip2 | 1.0.6-r7 |
| Medium | GO-2024-2687 | stdlib | 1.21.9 |
| Medium | GHSA-5cgq-3rg8-m6cv | golang.org/ | 0.52.0 |
| Medium | ALPINE-CVE-2019-11068 | libxslt | 1.1.33-r1 |
| Medium | ALPINE-CVE-2019-6978 | gd | 2.2.5-r2 |
| Medium | GHSA-83g2-8m93-v3w7 | golang.org/ | 0.0.0-20210520170846-37e1c6afe023 |
| Medium | ALPINE-CVE-2019-14697 | musl | 1.1.20-r5 |
| Medium | ALPINE-CVE-2018-14550 | libpng | 1.6.37-r0 |
| Medium | GHSA-v778-237x-gjrc | golang.org/ | 0.31.0 |
| Medium | ALPINE-CVE-2019-19956 | libxml2 | 2.9.9-r2 |
| Medium | ALPINE-CVE-2019-1543 | openssl | 1.1.1b-r1 |
| Medium | ALPINE-CVE-2018-5711 | gd | 2.2.5-r2 |
| Medium | ALPINE-CVE-2019-1551 | openssl | 1.1.1d-r2 |
| Medium | ALPINE-CVE-2021-36159 | apk-tools | 2.10.7-r0 |
| Medium | GHSA-vvpx-j8f3-3w6h | golang.org/ | 0.7.0 |
| Medium | ALPINE-CVE-2019-18197 | libxslt | 1.1.33-r2 |
| Medium | GHSA-8c26-wmh5-6g9v | golang.org/ | 0.0.0-20220314234659-1baeb1ce4c0b |
| Medium | GHSA-4374-p667-p6c8 | golang.org/ | 0.17.0 |
| Medium | ALPINE-CVE-2021-23841 | openssl | 1.1.1j-r0 |
| Medium | ALPINE-CVE-2018-14553 | gd | 2.2.5-r3 |
| Medium | ALPINE-CVE-2020-1971 | openssl | 1.1.1i-r0 |
| Medium | ALPINE-CVE-2019-7317 | libpng | 1.6.37-r0 |
| Medium | GHSA-69cg-p879-7622 | golang.org/ | 0.0.0-20220906165146-f3363e06e74c |
| Medium | GHSA-3vm4-22fp-5rfm | golang.org/ | 0.0.0-20201216223049-8b5274cf687f |
| Medium | GHSA-p77j-4mvh-x3m3 | google.golang.org/ | 1.79.3 |
| Medium | ALPINE-CVE-2019-2201 | libjpeg-turbo | 1.5.3-r6 |
| Medium | ALPINE-CVE-2021-42380 | busybox | 1.31.1-r11 |
| Medium | GHSA-cjjc-xp8v-855w | golang.org/ | 0.0.0-20200124225646-8b5121be2f68 |
| Medium | ALPINE-CVE-2020-24977 | libxml2 | 2.9.9-r3 |
| Medium | ALPINE-CVE-2021-42379 | busybox | 1.31.1-r11 |
| Medium | ALPINE-CVE-2021-42381 | busybox | 1.31.1-r11 |
| Medium | ALPINE-CVE-2021-42385 | busybox | 1.31.1-r11 |
| Medium | ALPINE-CVE-2021-42378 | busybox | 1.31.1-r11 |
| Medium | ALPINE-CVE-2021-42382 | busybox | 1.31.1-r11 |
| Medium | ALPINE-CVE-2021-42384 | busybox | 1.31.1-r11 |
| Medium | ALPINE-CVE-2021-42386 | busybox | 1.31.1-r11 |
| Medium | ALPINE-CVE-2019-13117 | libxslt | 1.1.33-r3 |
| Medium | ALPINE-CVE-2018-14048 | libpng | 1.6.37-r0 |
| Medium | ALPINE-CVE-2019-1549 | openssl | 1.1.1d-r0 |
Indexed versions
| Version | Published | App version | Vulnerabilities | Radar Score |
|---|---|---|---|---|
| 4.3.18latest | 2 years ago | 1.15.9-alpine | 31167179 | 3,958 |
The latest version and the previous major, as selected nightly from the repository’s index.
README badge
Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.