From 0a79db68cc540b52f2d6516fb20f05dc2f7513f0 Mon Sep 17 00:00:00 2001 From: Jan Larwig Date: Thu, 1 Oct 2026 10:53:36 +0200 Subject: [PATCH] docs: changelog for v7.15.5 Signed-off-by: Jan Larwig --- CHANGELOG.md | 20 ++++++++++++++++++-- 1 file changed, 18 insertions(+), 2 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 21867327..7e3d73ff 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -12,16 +12,32 @@ ## Release Highlights +- 🔵 Golang version upgrade to v1.26.8 + - Upgrade of all dependencies to their latest versions +- 🕵️‍♀️ Vulnerabilities have been addressed + - [CVE-2026-56855](https://nvd.nist.gov/vuln/detail/CVE-2026-56855) + - [CVE-2026-78662](https://nvd.nist.gov/vuln/detail/CVE-2026-78662) + - [CVE-2026-84304](https://nvd.nist.gov/vuln/detail/CVE-2026-84304) + - [CVE-2026-84445](https://nvd.nist.gov/vuln/detail/CVE-2026-84445) + ## Important Notes The Bitbucket provider `--bitbucket-team` flag got deprecated and we added `--bitbucket-workspace` flag to restrict logins to members of a specific workspace instead of a team. The `--bitbucket-team` flag is still supported and will act like workspace but will be removed in a future release. Please update your configuration to use the new `--bitbucket-workspace` flag. For more information, refer to [Bitbucket teams API deprecation](https://developer.atlassian.com/cloud/bitbucket/bitbucket-api-teams-deprecation/). Additionally refer to OAuth client configuration for Bitbucket provider in the [documentation](https://oauth2-proxy.github.io/oauth2-proxy/configuration/providers/bitbucket/). for changes in the scopes (Account>Read) is now required if you restrict by workspace. +Security Advisories: + +- (Critical) [GHSA-63jm-59jj-478j](https://github.com/oauth2-proxy/oauth2-proxy/security/advisories/GHSA-63jm-59jj-478j) Authentication bypass via inconsistent skip-auth path interpretation +- (Critical) [GHSA-wr5q-7wxw-x568](https://github.com/oauth2-proxy/oauth2-proxy/security/advisories/GHSA-wr5q-7wxw-x568) Authentication bypass via spoofed client-IP headers in OAuth2 Proxy +- (Moderate) [GHSA-hhqp-vx7f-5c6m](https://github.com/oauth2-proxy/oauth2-proxy/security/advisories/GHSA-hhqp-vx7f-5c6m) Credential disclosure through OAuth callback error logging + +Read more below + ## Critical Fixes For a small subset of deployments these fixes might be breaking change for the sake of fixing trust/security boundaries. -### (Critical) [GHSA-63jm-59jj-478j](https://github.com/oauth2-proxy/oauth2-proxy/security/advisories/GHSA-63jm-59jj-478j) Authentication bypass via inconsistent skip-auth path interpretation +### [GHSA-63jm-59jj-478j](https://github.com/oauth2-proxy/oauth2-proxy/security/advisories/GHSA-63jm-59jj-478j) Authentication bypass via inconsistent skip-auth path interpretation **Skip-auth path matching is now stricter**: `--skip-auth-route` and `--skip-auth-regex` no longer grant exemptions for invalid or ambiguous paths, even when a positive or negated rule would otherwise match. This includes dot @@ -42,7 +58,7 @@ matching behavior. The fix does not rewrite upstream request targets or unconditionally reject authenticated requests; existing router behavior and separately configured exemptions remain unchanged. -### (Critical) [GHSA-wr5q-7wxw-x568](https://github.com/oauth2-proxy/oauth2-proxy/security/advisories/GHSA-wr5q-7wxw-x568) Authentication bypass via spoofed client-IP headers in OAuth2 Proxy +### [GHSA-wr5q-7wxw-x568](https://github.com/oauth2-proxy/oauth2-proxy/security/advisories/GHSA-wr5q-7wxw-x568) Authentication bypass via spoofed client-IP headers in OAuth2 Proxy **Trusted client-IP resolution now enforces trusted proxy boundaries**: When `--reverse-proxy` is enabled, client-IP headers configured via `--real-client-ip-header` are accepted only from direct peers that match