GO-2024-2479: Authentik vulnerable to PKCE downgrade attack in goauthentik.io
GO-2024-3085: GoAuthentik vulnerable to Insufficient Authorization for several API endpoints in goauthentik.io
GO-2025-3822: Authentik has insufficient check for account active status when authenticating with OAuth/SAML Sources in goauthentik.io
GO-2025-4136: authentik's invitation expiry is delayed by at least 5 minutes in goauthentik.io
GO-2025-4137: authentik allows a deactivated Service account to authenticate to OAuth in goauthentik.io