OAuth2 Proxy's session cookies are not cleared when rendering sign-in page
Low severity
GitHub Reviewed
Published
Apr 14, 2026
in
oauth2-proxy/oauth2-proxy
•
Updated Apr 15, 2026
Package
Affected versions
>= 7.11.0, < 7.15.2
Patched versions
7.15.2
Description
Published to the GitHub Advisory Database
Apr 14, 2026
Reviewed
Apr 14, 2026
Published by the National Vulnerability Database
Apr 14, 2026
Last updated
Apr 15, 2026
Impact
A regression introduced in v7.11.0 is preventing OAuth2 Proxy from clearing the session cookie when rendering the sign-in page.
This only impacts deployments that rely on the sign-in page as part of their logout flow. In those setups, a user may be shown the sign-in page while the existing session cookie remains valid, so the browser session is not actually logged out. On shared workstations be it browsers or devices, a subsequent user could continue to use the previous user's authenticated session.
Deployments that use a dedicated logout/sign-out endpoint to terminate sessions are not affected.
Patches
This issue is fixed in v7.15.2.
Workarounds
Do not rely on the sign-in page to clear an existing session. Instead:
References