PingFederate 12.0.10 (October 2025)
Resolved issues
Host header redirect
Security PF-37460
We’ve fixed a security vulnerability that could have allowed malicious parties to redirect PingFederate admin console traffic using a spoofed Host header.
Virtual hostname accuracy in email notifications
Fixed PF-37964
We’ve fixed a defect where a template variable incorrectly used the primary PingFederate base URL instead of the virtual host name in some email notifications.
HTML flow login and Authentication API
Fixed PF-38039
We’ve fixed a defect that could potentially allow a user to access an HTML browser sign-on page when the Authentication API redirectless mode is used.
Learn more in PingFederate unexpected template rendering in redirectless mode in the Ping Identity Support Knowledge Base.