From 5f42ecbd3436c8bfb64454a1b7e2e3de11256cc8 Mon Sep 17 00:00:00 2001 From: Derek Date: Tue, 6 Oct 2026 12:47:54 +1100 Subject: [PATCH 1/2] fix(deps): bump oauth2-proxy to v7.15.5 for two critical auth bypasses oauth2-proxy v7.15.5 fixes GHSA-63jm-59jj-478j (skip-auth path confusion) and GHSA-wr5q-7wxw-x568 (spoofed client-IP headers). The three auth-profile proxies take it as tag@sha256, multi-arch. Our proxies set no skip-auth routes and no trusted-proxy client-IP rules, so the stricter matching changes nothing for them. --- docker-compose.yml | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/docker-compose.yml b/docker-compose.yml index 2ca160a..b6f6b46 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -1666,7 +1666,7 @@ services: # =========================================================================== oauth2-proxy-kafbat: - image: quay.io/oauth2-proxy/oauth2-proxy:${DFE_OAUTH2_PROXY_VERSION:-v7.15.4@sha256:b1b2021fe8f4004573e8d690dec6c7bb29cc44364572cf8510a05bf3a0ae2ded} + image: quay.io/oauth2-proxy/oauth2-proxy:${DFE_OAUTH2_PROXY_VERSION:-v7.15.5@sha256:8498b0d0ef0a7b29686414000a08aee467f02d0299c9ed1e006a8f33fc017916} container_name: ${DFE_CONTAINER_PREFIX:-}dfe-oauth2-proxy-kafbat profiles: ["auth"] restart: unless-stopped @@ -1683,7 +1683,7 @@ services: required: false oauth2-proxy-hyperdx: - image: quay.io/oauth2-proxy/oauth2-proxy:${DFE_OAUTH2_PROXY_VERSION:-v7.15.4@sha256:b1b2021fe8f4004573e8d690dec6c7bb29cc44364572cf8510a05bf3a0ae2ded} + image: quay.io/oauth2-proxy/oauth2-proxy:${DFE_OAUTH2_PROXY_VERSION:-v7.15.5@sha256:8498b0d0ef0a7b29686414000a08aee467f02d0299c9ed1e006a8f33fc017916} container_name: ${DFE_CONTAINER_PREFIX:-}dfe-oauth2-proxy-hyperdx profiles: ["auth"] restart: unless-stopped @@ -1710,7 +1710,7 @@ services: # and name as the app proxy above, and cookies are not port-scoped, so signing # in at the app authorises this one too. oauth2-proxy-hyperdx-api: - image: quay.io/oauth2-proxy/oauth2-proxy:${DFE_OAUTH2_PROXY_VERSION:-v7.15.4@sha256:b1b2021fe8f4004573e8d690dec6c7bb29cc44364572cf8510a05bf3a0ae2ded} + image: quay.io/oauth2-proxy/oauth2-proxy:${DFE_OAUTH2_PROXY_VERSION:-v7.15.5@sha256:8498b0d0ef0a7b29686414000a08aee467f02d0299c9ed1e006a8f33fc017916} container_name: ${DFE_CONTAINER_PREFIX:-}dfe-oauth2-proxy-hyperdx-api profiles: ["auth"] restart: unless-stopped From dd2cd33e42c1c354ff1423fd085c33e5311c9862 Mon Sep 17 00:00:00 2001 From: Derek Date: Tue, 6 Oct 2026 14:44:52 +1100 Subject: [PATCH 2/2] fix(deps): point the example oauth2-proxy override at v7.15.5 --- .env.example | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.env.example b/.env.example index ba2457f..db4f184 100644 --- a/.env.example +++ b/.env.example @@ -195,7 +195,7 @@ # DFE_OAUTH2_PROXY_COOKIE_SECURE=false ## Per-surface override of DFE_EXTERNAL_ORIGIN, which it follows when unset. # DFE_OAUTH2_PROXY_EXTERNAL_ORIGIN= -# DFE_OAUTH2_PROXY_VERSION=v7.15.4@sha256:b1b2021fe8f4004573e8d690dec6c7bb29cc44364572cf8510a05bf3a0ae2ded +# DFE_OAUTH2_PROXY_VERSION=v7.15.5@sha256:8498b0d0ef0a7b29686414000a08aee467f02d0299c9ed1e006a8f33fc017916 ## ============================================================================