Live stack monitoring for frameworks, packages, and vendor incidents
Feed synced 11h agoSecurity news for developers, not just security teams.
HackTribune turns supply-chain incidents, framework advisories, and malicious package reports into searchable incident pages, watchlists, and upgrade-worthy alerts.
5,404
incidents tracked
1,661
exploited in the wild
11
ecosystems covered
Verified against official advisory sources
Latest incidents
View all →UNKNOWNunknown
Nashville uses eminent domain to block data center near zoo
HIGHunknown
keycloak-services: keycloak-services: SAML IdP-initiated broker login bypasses link-only restriction
keycloak-services: keycloak-services: SAML IdP-initiated broker login bypasses link-only restriction
HIGHunknown
keycloak-services: keycloak-services: Default DCR policy allows role forgery via User Property mappers
keycloak-services: keycloak-services: Default DCR policy allows role forgery via User Property mappers
MEDIUMunknown
keycloak-services: keycloak-services: Unbounded metric cardinality in user event metrics via request-controlled error text
keycloak-services: keycloak-services: Unbounded metric cardinality in user event metrics via request-controlled error text
MEDIUMunknown
keycloak-services: keycloak-services: LDAP entry-DN user search bypasses configured users DN boundary
keycloak-services: keycloak-services: LDAP entry-DN user search bypasses configured users DN boundary
HIGHunknown
keycloak-services: keycloak-services: Authorization bypass via unnormalized URI matching in PathMatcher
keycloak-services: keycloak-services: Authorization bypass via unnormalized URI matching in PathMatcher