PingFederate 12.3.5 (February 2026)
Resolved issues
User Enumeration in Policy Password Reset
Security PF-38628
PingFederate now prevents user enumeration in the Policy mode Password Reset flow by eliminating the observable difference between valid and invalid usernames.
Serialized OGNL Java objects
Fixed PF-37405
We’ve fixed a defect that caused JSON objects using OGNL expressions included in JWT request objects sent to the OIDC provider in OIDC IdP connections not to be serialized properly.