
oathkeeper
A cloud native Identity & Access Proxy / API (IAP) and Access Control Decision API that authenticates, authorizes, and mutates incoming HTTP(s)…

A cloud native Identity & Access Proxy / API (IAP) and Access Control Decision API that authenticates, authorizes, and mutates incoming HTTP(s)…

Collaborative Passwords Manager

A reverse proxy like nginx, built on pingora, simple and efficient.

Lightweight edge HTTP(S) server and reverse proxy with automatic SSL, Docker/Consul discovery, per-route authentication, rate limiting, and…

Corelight Sensor API command-line client

A small, auditable, terminating, deterministic micro-policy engine

SAML v2.0 bindings in Java using JAXB

A high-performance TAXII (Trusted Automated eXchange of Indicator Information) server written in Rust.

PoC: changedetection.io settings blind-merge mass assignment (CVE-2026-71204, Medium 6.3)

PoC: Grafana Editor role deletes protected contact points (CVE-2026-72585, Medium 6.5)

PlaceOS authentication service and API gatekeeper.

CVE-2026-31816 - Budibase Authentication Bypass to RCE

PHP 8.4+ security library (mirror)

Alibab-Nacos-Unauthorized-Reset PWD

The VTEX Checkout Service exposes OrderForm data through the endpoints `/api/checkout/pub/orderForm/{orderFormId}` and `/attachments/*`. These…

Missing Authorization in inseriswiss inseri core inseri-core allows Exploiting Incorrectly Configured Access Control Security Levels.This issue…

gRPC-Go RBAC Authorization Policy Bypass via Missing `:path` Slash (Auth Bypass)

Post-quantum hybrid encryption library combining X25519 + ML-KEM-768 with AES-256-GCM