
authelia
The Single Sign-On Multi-Factor portal for web apps. OpenID Certified™ and Post-Quantum Cryptography Ready.

The Single Sign-On Multi-Factor portal for web apps. OpenID Certified™ and Post-Quantum Cryptography Ready.

High-performance multi-protocol AAA server for RADIUS, DHCPv4/v6, DNS, TACACS+, and VMPS, centralizing network authentication, authorization, and…

Protect your SSH keys with your Mac's Secure Enclave

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

Workload identity platform that attests running services, issues SPIFFE IDs/SVIDs, and enables mTLS and JWT authentication for Kubernetes,…

CLI framework for deploying and managing serverless applications on AWS Lambda with YAML infrastructure, local development, and multi-language…


Bitwarden client apps (web, browser extension, desktop, and cli).

A reverse proxy like nginx, built on pingora, simple and efficient.

Declarative policy engine that enables authorization and policy enforcement across services, Kubernetes, Terraform, Docker, and APIs using the Rego…

The most comprehensive authentication framework

Self-hosted identity management platform providing WebAuthn passkeys, OAuth2/OIDC SSO, SSH key distribution, RADIUS and LDAP integration for modern…

**CVE-2026-18963** — unauthenticated Keycloak account takeover via the reset-credentials flow.

SSH agent that creates and manages TPM-sealed keys for hardware-bound authentication, supporting key generation, import, wrapping, PIN protection,…

A local-only journal with serious encryption. Free, open source, and never touches the internet.

A free, secure and open source app for Android to manage your 2-step verification tokens.

Just-in-time API keys for AI agents - and any other process you route through it: the caller only ever sees a placeholder.

Proof-of-concept exploit for CVE-2026-18963, a Keycloak reset-credentials bypass leading to account takeover. Demonstrates the vulnerability and…