If you discover a security issue in ForgePoint.Identity, please open a private GitHub security advisory on the repository.
This 10.x line includes a fix for CVE-2024-39694 (open redirect via crafted local URLs). IdentityServer4 4.1.2 and earlier remain affected.
Do not file public issues for unreleased vulnerabilities until a fix is available.