Skip to content

Update of instructions to reporty vulnerabilities and team structure#718

Merged
ahus1 merged 3 commits intokeycloak:mainfrom
abstractj:update-security-page
Mar 19, 2026
Merged

Update of instructions to reporty vulnerabilities and team structure#718
ahus1 merged 3 commits intokeycloak:mainfrom
abstractj:update-security-page

Conversation

@abstractj
Copy link
Contributor

No description provided.

Signed-off-by: Bruno Oliveira da Silva <bruno@abstractj.com>
@abstractj abstractj requested a review from a team March 16, 2026 14:37
<h3>Coordinated Vulnerability Disclosure</h3>
<p>To report a security vulnerability in the Keycloak codebase, send an email to <a href="mailto:keycloak-security@googlegroups.com">keycloak-security@googlegroups.com</a>. Please test against the <strong>latest version</strong> of Keycloak, include the affected version in your report, provide detailed instructions on how to reproduce the issue with a <a href="https://stackoverflow.com/help/minimal-reproducible-example">minimal and reproducible example</a>, and include your contact information for acknowledgements. If you are reporting known CVEs related to third-party libraries used in Keycloak, please <a href="https://github.com/keycloak/keycloak/issues/new/choose">create a new GitHub issue</a>.</p>
<p>If you would like to collaborate on a fix for the security vulnerability, please include your GitHub username in the email, and we will provide you access to a temporary private fork where we can work together.</p>
<p>To report a security vulnerability in the Keycloak codebase, send an email to <a href="mailto:keycloak-security@googlegroups.com">keycloak-security@googlegroups.com</a>. Security researchers who wish to participate in our dedicated vulnerability reward program should refer to <a href="https://yeswehack.com/programs/keycloak-bug-bounty-program"> the Bug Bounty Program's platform</a> for submissions and details. Please test against the <strong>latest version</strong> of Keycloak, include the affected version in your report, provide detailed instructions on how to reproduce the issue with a <a href="https://stackoverflow.com/help/minimal-reproducible-example">minimal and reproducible example</a>, and include your contact information for acknowledgements. If you are reporting known CVEs related to third-party libraries used in Keycloak, please <a href="https://github.com/keycloak/keycloak/issues/new/choose">create a new GitHub issue</a>.</p>
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The Bug Bounty should be removed as it is currently closed. We're not sure when and if it will be re-openend.

@ahus1
Copy link
Member

ahus1 commented Mar 18, 2026

@abstractj - while I added my view on the "evidence" above, I'm ok to discuss that in another issue.

The only change that IMHO remains is to remove the reference to the bug bounty, then it is good to be merged.

abstractj and others added 2 commits March 19, 2026 09:01
Co-authored-by: Alexander Schwartz <alexander.schwartz@gmx.net>
Signed-off-by: Bruno Oliveira da Silva <bruno@abstractj.com>
Signed-off-by: Bruno Oliveira da Silva <bruno@abstractj.com>
@abstractj abstractj requested review from ahus1 and sschu March 19, 2026 12:07
@abstractj
Copy link
Contributor Author

@ahus1 @sschu after your approval I can squash and rebase.

@ahus1 ahus1 merged commit 57a20b8 into keycloak:main Mar 19, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants