oauth2-proxy 4.3.18 Helm chart
presto-loadbalancerScored 14 Sept 2026
A reverse proxy that provides authentication with Google, Github or other providers
Version 4.3.18 2 years agodeploys tag 1.15.9-alpine 0Artifact Hub
oauth2-proxy 4.3.18 deploys 2 container images: library/nginx and quay.io/oauth2-proxy/oauth2-proxy. Across them, 260 findings — 3 critical, 11 high — 2 on CISA KEV. The highest contribution is ALPINE-CVE-2020-15999 in freetype 2.9.1-r2, fixed in 2.9.1-r3. Chart.yaml declares kubeVersion >=1.9.0-0; rendered for Kubernetes 1.9.0.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Container images
| Image | Tag | Vulnerabilities | Radar Score |
|---|---|---|---|
| library/ | 1.15.9-alpine | 23235 | 951 |
| quay.io/ | v6.1.1 | 1844174 | 3,007 |
Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.
Low findings
Low: findings whose contribution to the Radar Score is 1–14. Show every band
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Low | GHSA-89gr-r52h-f8rx | golang.org/ | 0.52.0 |
| Low | GHSA-jppx-rxg9-jmrx | golang.org/ | 0.52.0 |
| Low | GO-2021-0142 | stdlib | 1.13.15 |
| Low | GO-2021-0263 | stdlib | 1.16.10 |
| Low | GO-2023-1571 | stdlib | 1.19.6 |
| Low | GHSA-vp52-pcj8-j9qc | google.golang.org/ | 1.83.1 |
| Low | GO-2022-0435 | stdlib | 1.17.9 |
| Low | GO-2022-0288 | golang.org/ | 0.0.0-20211209124913-491a49abca63 |
| Low | GO-2022-0288 | stdlib | 1.16.12 |
| Low | GO-2021-0069 | stdlib | 1.14.12 |
| Low | GO-2023-2102 | stdlib | 1.20.10 |
| Low | GO-2022-0236 | stdlib | 1.15.12 |
| Low | GO-2021-0226 | stdlib | 1.14.8 |
| Low | GO-2021-0240 | stdlib | 1.15.13 |
| Low | GO-2021-0242 | stdlib | 1.15.13 |
| Low | GO-2021-0264 | stdlib | 1.16.10 |
| Low | GO-2022-0969 | stdlib | 1.18.6 |
| Low | GO-2021-0239 | stdlib | 1.15.13 |
| Low | GO-2021-0347 | stdlib | 1.16.15 |
| Low | GO-2021-0245 | stdlib | 1.15.15 |
| Low | GHSA-q4h4-gmj2-qvw2 | golang.org/ | 0.52.0 |
| Low | GO-2021-0319 | stdlib | 1.16.14 |
| Low | GHSA-w879-237q-wc7r | golang.org/ | 0.52.0 |
| Low | ALPINE-CVE-2019-1563 | openssl | 1.1.1d-r0 |
| Low | GHSA-2wrh-6pvc-2jm9 | golang.org/ | 0.13.0 |
| Low | GO-2022-0493 | stdlib | 1.17.10 |
| Low | GO-2021-0224 | stdlib | 1.13.13 |
| Low | GO-2021-0317 | stdlib | 1.16.14 |
| Low | GO-2023-2185 | stdlib | 1.20.11 |
| Low | GO-2021-0235 | stdlib | 1.14.14 |
| Low | GO-2022-0537 | stdlib | 1.17.13 |
| Low | GO-2021-0234 | stdlib | 1.15.9 |
| Low | GHSA-c5q2-7r4c-mv6g | gopkg.in/ | no fix listed |
| Low | ALPINE-CVE-2021-23839 | openssl | 1.1.1j-r0 |
| Low | GO-2023-1703 | stdlib | 1.19.8 |
| Low | GO-2021-0241 | stdlib | 1.15.13 |
| Low | GO-2022-0521 | stdlib | 1.17.12 |
| Low | GO-2022-0477 | stdlib | 1.17.11 |
| Low | GO-2026-4341 | stdlib | 1.24.12 |
| Low | GO-2022-0533 | stdlib | 1.17.11 |
| Low | ALPINE-CVE-2019-13627 | libgcrypt | 1.8.5-r0 |
| Low | GO-2022-0523 | stdlib | 1.17.12 |
| Low | GO-2024-2887 | stdlib | 1.21.11 |
| Low | ALPINE-CVE-2019-1547 | openssl | 1.1.1d-r0 |
| Low | GO-2022-0522 | stdlib | 1.17.12 |
| Low | GO-2022-0527 | stdlib | 1.17.12 |
| Low | GO-2022-0524 | stdlib | 1.17.12 |
| Low | GO-2023-1704 | stdlib | 1.19.8 |
| Low | GO-2022-0289 | stdlib | 1.16.12 |
| Low | GO-2021-0223 | stdlib | 1.13.13 |
Indexed versions
| Version | Published | App version | Vulnerabilities | Radar Score |
|---|---|---|---|---|
| 4.3.18latest | 2 years ago | 1.15.9-alpine | 31167179 | 3,958 |
The latest version and the previous major, as selected nightly from the repository’s index.
README badge
Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.