
CVE-2026-23552
CVE-2026-23552 - Cross-Realm Token Acceptance in camel-keycloak

CVE-2026-23552 - Cross-Realm Token Acceptance in camel-keycloak

Burp Suite extension for API security testing with 15 attack types, 108+ payloads, intelligent fuzzing, BOLA/IDOR detection, AI integration, and…

An organizational asset and vulnerability management tool, with Jira integration, designed for generating application security reports.

Burp Suite Extension useful to verify OAUTHv2 and OpenID security

cMCP: Confidential MCP Gateway. Hardware-attested policy enforcement for MCP tool calls.

MCP is being adopted rapidly. Security guidance is lagging behind. This checklist gives security engineers, platform teams, and technical leaders a…

Python script to bypass Azure APIM signup when UI is disabled, this is different from the CVE-2025-66390 as it does not require you to setup anything…

Runtime security gateway for AI agents: cryptographically attests tool calls, enforces policies, sandboxes execution, and logs tamper-evident audit…

A unified, security-first wire protocol for tool access and agent coordination. UAP eliminates CVE-2025-49596 and MCP tool-poisoning vulnerabilities…

Checklist of the most important security countermeasures when designing, testing, and releasing your API

:snake: A toolkit for testing, tweaking and cracking JSON Web Tokens

Damn Vulnerable GraphQL Application is an intentionally vulnerable GraphQL service implementation designed for learning about and practising GraphQL…

A vulnerability scanner that detects CVE-2021-37580 vulnerabilities.

The Secure CommsOS™ for mission-critical operations

The Symfony PHP framework

OpenID Certified OAuth 2.0 and OpenID Connect provider for token issuance, client management, JWKS, and login/consent flow orchestration via headless…

API-first identity and user management system for cloud-native applications. Handles login, registration, MFA, recovery, and profile management with…

Authorization engine for context-aware access control with YAML policies, RBAC/ABAC support, check/plan APIs, and GitOps-friendly deployment.