oauth2-proxy Helm chart
presto-loadbalancerScored 14 Sept 2026
A reverse proxy that provides authentication with Google, Github or other providers
Latest 4.3.18 2 years agodeploys tag 1.15.9-alpine 0Artifact Hub
oauth2-proxy 4.3.18 deploys 2 container images: library/nginx and quay.io/oauth2-proxy/oauth2-proxy. Across them, 260 findings — 3 critical, 11 high — 2 on CISA KEV. The highest contribution is ALPINE-CVE-2020-15999 in freetype 2.9.1-r2, fixed in 2.9.1-r3. Chart.yaml declares kubeVersion >=1.9.0-0; rendered for Kubernetes 1.9.0.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Container images
| Image | Tag | Vulnerabilities | Radar Score |
|---|---|---|---|
| library/ | 1.15.9-alpine | 23235 | 951 |
| quay.io/ | v6.1.1 | 1844174 | 3,007 |
Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.
Vulnerabilities
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Medium | GHSA-w73w-5m7g-f7qc | github.com/ | no fix listed |
| Medium | ALPINE-CVE-2021-42383 | busybox | 1.31.1-r11 |
| Medium | ALPINE-CVE-2018-14498 | libjpeg-turbo | 1.5.3-r5 |
| Medium | GHSA-xrjj-mj9h-534m | golang.org/ | 0.4.0 |
| Medium | GHSA-5rcv-m4m3-hfh7 | golang.org/ | 0.3.3 |
| Medium | ALPINE-CVE-2019-13118 | libxslt | 1.1.33-r3 |
| Medium | GHSA-h86h-8ppg-mxmh | golang.org/ | 0.0.0-20210428140749-89ef3d95e781 |
| Medium | GHSA-r5c5-pr8j-pfp7 | golang.org/ | 0.0.0-20190320223903-b7391e95e576 |
| Medium | GHSA-69ch-w2m2-3vjp | golang.org/ | 0.3.8 |
| Medium | ALPINE-CVE-2019-11038 | gd | 2.2.5-r3 |
| Medium | GO-2022-0433 | stdlib | 1.17.9 |
| Medium | ALPINE-CVE-2020-14155 | pcre | 8.42-r2 |
| Medium | GHSA-ppp9-7jff-5vj2 | golang.org/ | 0.3.7 |
| Medium | GHSA-8r3f-844c-mc37 | google.golang.org/ | 1.33.0 |
| Medium | GHSA-x527-x647-q7gg | golang.org/ | 0.52.0 |
| Medium | GHSA-gwc9-m7rh-j2ww | golang.org/ | 0.0.0-20211202192323-5770296d904e |
| Medium | GHSA-vgwf-h737-ff37 | golang.org/ | 0.52.0 |
| Medium | GHSA-f5wc-c3c7-36mc | golang.org/ | 0.52.0 |
| Medium | GO-2021-0243 | stdlib | 1.15.14 |
| Medium | GO-2022-0273 | stdlib | 1.16.8 |
| Medium | GHSA-p782-xgp4-8hr8 | golang.org/ | 0.0.0-20220412211240-33da011f77ad |
| Medium | ALPINE-CVE-2019-12904 | libgcrypt | 1.8.4-r1 |
| Medium | GHSA-x3jr-pf6g-c48f | golang.org/ | 0.0.0-20190424203555-c05e17bb3b2d |
| Medium | GHSA-rm3j-f69w-wqmq | golang.org/ | 0.52.0 |
| Medium | GHSA-hcg3-q754-cr77 | golang.org/ | 0.35.0 |
| Medium | GO-2022-1144 | stdlib | 1.18.9 |
| Medium | GHSA-6v2p-p543-phr9 | golang.org/ | 0.27.0 |
| Low | GHSA-89gr-r52h-f8rx | golang.org/ | 0.52.0 |
| Low | GHSA-jppx-rxg9-jmrx | golang.org/ | 0.52.0 |
| Low | GO-2021-0142 | stdlib | 1.13.15 |
| Low | GO-2021-0263 | stdlib | 1.16.10 |
| Low | GO-2023-1571 | stdlib | 1.19.6 |
| Low | GHSA-vp52-pcj8-j9qc | google.golang.org/ | 1.83.1 |
| Low | GO-2022-0435 | stdlib | 1.17.9 |
| Low | GO-2022-0288 | stdlib | 1.16.12 |
| Low | GO-2022-0288 | golang.org/ | 0.0.0-20211209124913-491a49abca63 |
| Low | GO-2021-0069 | stdlib | 1.14.12 |
| Low | GO-2023-2102 | stdlib | 1.20.10 |
| Low | GO-2022-0236 | stdlib | 1.15.12 |
| Low | GO-2021-0226 | stdlib | 1.14.8 |
| Low | GO-2021-0240 | stdlib | 1.15.13 |
| Low | GO-2021-0242 | stdlib | 1.15.13 |
| Low | GO-2021-0264 | stdlib | 1.16.10 |
| Low | GO-2022-0969 | stdlib | 1.18.6 |
| Low | GO-2021-0239 | stdlib | 1.15.13 |
| Low | GO-2021-0347 | stdlib | 1.16.15 |
| Low | GO-2021-0245 | stdlib | 1.15.15 |
| Low | GHSA-q4h4-gmj2-qvw2 | golang.org/ | 0.52.0 |
| Low | GO-2021-0319 | stdlib | 1.16.14 |
| Low | GHSA-w879-237q-wc7r | golang.org/ | 0.52.0 |
Indexed versions
| Version | Published | App version | Vulnerabilities | Radar Score |
|---|---|---|---|---|
| 4.3.18latest | 2 years ago | 1.15.9-alpine | 31167179 | 3,958 |
The latest version and the previous major, as selected nightly from the repository’s index.
README badge
Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.