<
p>To report a security vulnerability in the Keycloak codebase, send an email to <
a href=
"mailto:[email protected]">
[email protected]</
a>.
Security researchers who wish to participate in our dedicated vulnerability reward program should refer to <a href="https://yeswehack.com/programs/keycloak-bug-bounty-program"> the Bug Bounty Program's platform</a> for submissions and details. Please test against the <
strong>latest version</
strong> of Keycloak, include the affected version in your report, provide detailed instructions on how to reproduce the issue with a <
a href=
"https://stackoverflow.com/help/minimal-reproducible-example">minimal and reproducible example</
a>, and include your contact information for acknowledgements. If you are reporting known CVEs related to third-party libraries used in Keycloak, please <
a href=
"https://github.com/keycloak/keycloak/issues/new/choose">create a new GitHub issue</
a>.</
p>
0 commit comments