-
Notifications
You must be signed in to change notification settings - Fork 8.6k
All issues
Issue creation is restricted in this repository
Issues
is:issue state:open
is:issue state:open
Search results
Deprecate introspection endpoint 'jwt' extension
area/oidcIndicates an issue on OIDC areaIndicates an issue on OIDC areaStatus: Open.Google Identity Provider fails with invalid_client after enabling KC_HOSTNAME_ADMIN (Keycloak 25.0.6)
kind/bugCategorizes a PR related to a bugCategorizes a PR related to a bugStatus: Open.#51025 In keycloak/keycloak;[Admin Console] 500 Error on resource endpoint during Create Permission (Works in Dev, Fails in Test environment)
kind/bugCategorizes a PR related to a bugCategorizes a PR related to a bugStatus: Open.Multivalued attributes ignore inputType
kind/bugCategorizes a PR related to a bugCategorizes a PR related to a bugStatus: Open.#51023 In keycloak/keycloak;Typo in "Integrating with Model Context Protocol (MCP)" (mcp-authz-server.adoc)
kind/bugCategorizes a PR related to a bugCategorizes a PR related to a bugStatus: Open.#51018 In keycloak/keycloak;Standard Token Exchange V2 refuses cross-client exchange of DPoP-bound subject_tokens
kind/bugCategorizes a PR related to a bugCategorizes a PR related to a bugStatus: Open.Extend CIMD executor to cover PAR endpoint
kind/enhancementCategorizes a PR related to an enhancementCategorizes a PR related to an enhancementStatus: Open.#51007 In keycloak/keycloak;[CVE-2026-16104] Authenticator config surfaces expose raw reCAPTCHA secrets
kind/cveIssues identified as CVEs on third-party dependencies, or issues which Keycloak is not affectedIssues identified as CVEs on third-party dependencies, or issues which Keycloak is not affectedpriority/importantMust be worked on very soonMust be worked on very soonStatus: Open.Legacy OIDC broker token exchange accepts ID tokens issued to a different audience
kind/bugCategorizes a PR related to a bugCategorizes a PR related to a bugpriority/importantMust be worked on very soonMust be worked on very soonStatus: Open.[CVE-2026-16089] Authorization codes can be retargeted to another client session
area/oidcIndicates an issue on OIDC areaIndicates an issue on OIDC areakind/cveIssues identified as CVEs on third-party dependencies, or issues which Keycloak is not affectedIssues identified as CVEs on third-party dependencies, or issues which Keycloak is not affectedpriority/importantMust be worked on very soonMust be worked on very soonStatus: Open.[CVE-2026-16105] Missing per-role authorization on RoleContainerResource composite endpoints
area/admin/rbacA label to track issues related to admin RBACA label to track issues related to admin RBACkind/cveIssues identified as CVEs on third-party dependencies, or issues which Keycloak is not affectedIssues identified as CVEs on third-party dependencies, or issues which Keycloak is not affectedpriority/importantMust be worked on very soonMust be worked on very soonStatus: Open.[CVE-2026-16108] Realm default-group reads disclose hidden groups under FGAP v2
kind/cveIssues identified as CVEs on third-party dependencies, or issues which Keycloak is not affectedIssues identified as CVEs on third-party dependencies, or issues which Keycloak is not affectedpriority/importantMust be worked on very soonMust be worked on very soonStatus: Open.