org.keycloak

174 tracked vulnerabilities.

CVE-2026-1518 LOW
Keycloak - Server-Side Request Forgery via CIBA Backchannel Notification Endpoint
Feb 02, 2026
CVSS 2.7
EPSS 0.00
CVE-2026-1190 LOW
Keycloak - SAML Response Expiration Bypass via Missing NotOnOrAfter Validation
Jan 26, 2026
CVSS 3.1
EPSS 0.00
CVE-2026-1035 LOW
Keycloak - Refresh Token Reuse Bypass via Non-Atomic Validation in TokenManager
Jan 21, 2026
CVSS 3.1
EPSS 0.00
CVE-2026-1180 MEDIUM
Keycloak - Server-Side Request Forgery via OpenID Connect Dynamic Client Registration
Jan 20, 2026
CVSS 5.8
EPSS 0.00
CVE-2026-0976 LOW
Keycloak - Path Filter Bypass via RFC-Compliant Matrix Parameters
Jan 15, 2026
CVSS 3.7
EPSS 0.00
CVE-2026-0707 MEDIUM
Keycloak - Authorization Bypass via Non-Standard Bearer Token Parsing
Jan 08, 2026
CVSS 5.3
EPSS 0.00
CVE-2025-12150 LOW
Keycloak < 26.4.4 - Improper Verification of Cryptographic Signature via WebAuthn Attestation Bypass
Feb 27, 2026
CVSS 3.1
EPSS 0.00
CVE-2025-11537 MEDIUM
Keycloak Quarkus Server < 26.6.0 - Sensitive Header Exposure in Verbose Log Format
Feb 10, 2026
CVSS 5.0
EPSS 0.00
CVE-2025-14778 MEDIUM
Keycloak < 26.2.13 - Incorrect Privilege Assignment in UserManagedPermissionService
Feb 09, 2026
CVSS 5.4
EPSS 0.00
CVE-2025-13881 LOW
Keycloak Services 26.5.0-26.5.1 - Unauthorized Sensitive Attribute Disclosure via UnmanagedAttributes Endpoint
Feb 02, 2026
CVSS 2.7
EPSS 0.00
CVE-2025-14083 LOW
Keycloak - Improper Access Control in Admin REST API
Jan 21, 2026
CVSS 2.7
EPSS 0.00
CVE-2025-14559 MEDIUM
Keycloak Services 26.5.0-26.5.1 - Unauthorized Token Issuance via Token Exchange Flow
Jan 21, 2026
CVSS 6.5
EPSS 0.00
CVE-2025-11419 HIGH
Keycloak < 26.0.16 - Unauthenticated Denial of Service via TLS 1.2 Client-Initiated Renegotiation
Dec 23, 2025
CVSS 7.5
EPSS 0.00
CVE-2025-14082 LOW
Keycloak < 26.5.0 - Unauthenticated Sensitive Role Metadata Exposure via Admin REST API
Dec 10, 2025
CVSS 2.7
EPSS 0.00
CVE-2025-13467 MEDIUM
Keycloak LDAP Federation < 26.4.6 - Authenticated Deserialization of Untrusted Data via LDAP Server Configuration
Nov 25, 2025
CVSS 5.5
EPSS 0.00
CVE-2025-11538 MEDIUM
Keycloak < 26.4.4 - Remote Code Execution via Debug Mode JDWP Port Binding
Nov 13, 2025
CVSS 6.8
EPSS 0.00
CVE-2025-12390 MEDIUM
Keycloak < 26.0.0 - Session Fixation via Incomplete Session Cleanup
Oct 28, 2025
CVSS 6.0
EPSS 0.00
CVE-2025-10939 LOW
Keycloak < 26.4.4 - Unauthenticated Admin Path Access via Proxy Path Normalization Bypass
Oct 28, 2025
CVSS 3.7
EPSS 0.00
CVE-2025-12110 MEDIUM
Keycloak < 26.4.3 - Insufficient Session Expiration via Offline Access Scope Removal
Oct 23, 2025
CVSS 5.4
EPSS 0.00
CVE-2025-11429 MEDIUM
Keycloak < 26.4.1 - Insufficient Session Expiration via Remember Me Setting
Oct 23, 2025
CVSS 5.4
EPSS 0.00
CVE-2025-10044 MEDIUM
Keycloak < 26.2.9 - Phishing via Unsanitized Error Description Parameter
Sep 05, 2025
CVSS 4.3
EPSS 0.00
CVE-2025-9162 MEDIUM
KeycloakRealmImport - Code Injection
Aug 21, 2025
CVSS 4.9
EPSS 0.00
CVE-2025-8419 MEDIUM
Keycloak < 26.2.8 - SMTP Injection via Email Registration
Aug 06, 2025
CVSS 5.3
EPSS 0.00
CVE-2025-7784 MEDIUM
Red Hat build of Keycloak - Privilege Escalation via Fine-Grained Admin Permissions
Jul 18, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-7365 HIGH
Keycloak - Authenticated Account Takeover via Identity Provider Login Email Verification
Jul 10, 2025
CVSS 7.1
EPSS 0.00