Repository Issue Activity (beta)

spring-projects/spring-security

Current issue state, recent activity, and per-issue timelines from the indexed issue data.

Open Issues
580
New in 7 Days
9
Closed in 7 Days
12
Average Open Age
631 days
Stale 30+ Days
527
Stale 90+ Days
456
Last 2 Weeks
DateOpenedClosedCommentsEventsOpen Backlog
2026-09-0700000
2026-09-060000580
2026-09-0500000
2026-09-0400000
2026-09-0359000
2026-09-0200000
2026-09-0120000
2026-08-3123000
2026-08-3000000
2026-08-2910000
2026-08-2810000
2026-08-2710000
2026-08-2600000
2026-08-2531000
This Week

Opened: 7

Closed: 9

Comments: 0

Events: 0

Top Labels
type: enhancement (925)
type: bug (590)
status: waiting-for-triage (386)
in: oauth2 (348)
in: web (221)
status: duplicate (196)
in: core (162)
in: build (156)
Issue Explorer
IssueAuthorStateLabelsCommentsReactionsUpdated

#11598 Make default expression handler in PrePostMethodSecurityConfiguration to use existing permission evaluator

Opened 4 years ago
GFriedrich
closed - completed
status: duplicate
in: config
type: enhancement
404 days ago

#19084 PrePostMethodSecurityConfiguration is missing a setter for custom PermissionEvaluator

Opened 5 months ago
Siggen
closed - completed
status: duplicate
in: core
type: enhancement
204 days ago

#19649 TokenType reference comparison is used in BearerTokenAuthentication

Opened 4 days ago
jzheaux
closed - completed
status: waiting-for-triage
type: bug
status: forward-port
004 days ago

#19648 TokenType reference comparison is used in BearerTokenAuthentication

Opened 4 days ago
jzheaux
closed - completed
status: waiting-for-triage
type: bug
status: forward-port
004 days ago

#19377 TokenType reference comparison is used in BearerTokenAuthentication

Opened 3 months ago
norbert-kiss-99
closed - completed
status: waiting-for-triage
type: bug
024 days ago

#19647 Header Writers should not corrupt Jetty HttpFields state in reactive ResponseBodyEmitter handlers

Opened 4 days ago
jzheaux
closed - completed
in: web
type: bug
status: forward-port
104 days ago

#19646 Header Writers should not corrupt Jetty HttpFields state in reactive ResponseBodyEmitter handlers

Opened 4 days ago
jzheaux
closed - completed
in: web
type: bug
status: forward-port
004 days ago

#9175 Thread-unsafe usage of HttpServletResponse corrupting jetty HttpFields state in reactive ResponseBodyEmitter handlers

Opened 6 years ago
SpComb
closed - completed
in: web
type: bug
27114 days ago

#19643 Expose JWKSourceBuilder options (cache TTL, refresh-ahead, outage tolerance) on JwkSetUriJwtDecoderBuilder

Opened 4 days ago
fkreisEnbw
open
in: oauth2
104 days ago

#19510 Improve readability and simplify null check in `ProviderManager.checkState()`

Opened 1 month ago
wsdf25867
closed - completed
status: waiting-for-triage
type: enhancement
004 days ago

#10826 Consider having ContentSecurityPolicyHeaderWriter supply a script nonce

Opened 5 years ago
jzheaux
open
in: web
type: enhancement
3125 days ago

#5767 No API to perform formLogin and logout on webflux

Opened 8 years ago
bkolb
open
status: ideal-for-contribution
805 days ago

#18457 Remove javadoc warnings for spring-security-ldap

Opened 8 months ago
rwinch
open
in: build
type: enhancement
305 days ago

#19639 Preserve the resource path in the default resource_metadata challenge

Opened 6 days ago
sherter
open
status: waiting-for-triage
type: enhancement
006 days ago

#19638 [Client] Support JWT for Client Authentication, as defined in RFC 7523

Opened 6 days ago
marvin-kolja
open
status: waiting-for-triage
type: enhancement
006 days ago

#19317 NoClassDefFound with version 7.1.0

Opened 3 months ago
bursauxa
open
status: waiting-for-triage
type: bug
1046 days ago

#19632 Turn Off Auto-merge for Maintenance Branch

Opened 7 days ago
jzheaux
closed - completed
in: build
type: task
status: forward-port
007 days ago

#19631 Turn Off Auto-merge for Maintenance Branch

Opened 7 days ago
jzheaux
closed - completed
in: build
type: task
007 days ago

#19424 Reactive RefreshOidcUserReactiveOAuth2AuthorizationSuccessHandler rotates the WebSession id on token refresh, stranding concurrent requests in a WebFlux BFF

Opened 2 months ago
dbauer-noreja
closed - completed
status: duplicate
type: bug
in: oauth2
837 days ago

#18458 Remove javadoc warnings for spring-security-messaging

Opened 8 months ago
rwinch
open
in: build
type: enhancement
707 days ago

#18443 Remove javadoc warnings

Opened 8 months ago
rwinch
open
in: build
type: enhancement
status: ideal-for-contribution
007 days ago

#19627 Fix for #18243 (CacheSaml2AuthenticationRequestRepository.saveAuthenticationRequest(..) throws IllegalArgumentException) is missing in 7.1.1

Opened 10 days ago
patrick-rosendaal
open
status: waiting-for-triage
type: bug
109 days ago

#19628 Spring security becomes unusable when OpenSAML is on the module path

Opened 9 days ago
raphw
open
status: waiting-for-triage
type: bug
009 days ago

#14245 Consider removing com.nimbusds:oauth2-oidc-sdk dependency

Opened 3 years ago
jgrandja
open
in: oauth2
type: breaks-passivity
7711 days ago

#19606 Spring Security between 6.3.10 (exclusive) and at least 6.5.11 (inclusive) breaks SAML signature validation due to namespace hoisting

Opened 11 days ago
martingrau-wps
open
status: waiting-for-triage
type: bug
0011 days ago

Rows per page:

1–25 of 1,862