org.keycloak
174 tracked vulnerabilities.
CVE-2026-1518
LOW
Keycloak - Server-Side Request Forgery via CIBA Backchannel Notification Endpoint
Feb 02, 2026
CVSS 2.7
EPSS 0.00
CVE-2026-1190
LOW
Keycloak - SAML Response Expiration Bypass via Missing NotOnOrAfter Validation
Jan 26, 2026
CVSS 3.1
EPSS 0.00
CVE-2026-1035
LOW
Keycloak - Refresh Token Reuse Bypass via Non-Atomic Validation in TokenManager
Jan 21, 2026
CVSS 3.1
EPSS 0.00
CVE-2026-1180
MEDIUM
Keycloak - Server-Side Request Forgery via OpenID Connect Dynamic Client Registration
Jan 20, 2026
CVSS 5.8
EPSS 0.00
CVE-2026-0976
LOW
Keycloak - Path Filter Bypass via RFC-Compliant Matrix Parameters
Jan 15, 2026
CVSS 3.7
EPSS 0.00
CVE-2026-0707
MEDIUM
Keycloak - Authorization Bypass via Non-Standard Bearer Token Parsing
Jan 08, 2026
CVSS 5.3
EPSS 0.00
CVE-2025-12150
LOW
Keycloak < 26.4.4 - Improper Verification of Cryptographic Signature via WebAuthn Attestation Bypass
Feb 27, 2026
CVSS 3.1
EPSS 0.00
CVE-2025-11537
MEDIUM
Keycloak Quarkus Server < 26.6.0 - Sensitive Header Exposure in Verbose Log Format
Feb 10, 2026
CVSS 5.0
EPSS 0.00
CVE-2025-14778
MEDIUM
Keycloak < 26.2.13 - Incorrect Privilege Assignment in UserManagedPermissionService
Feb 09, 2026
CVSS 5.4
EPSS 0.00
CVE-2025-13881
LOW
Keycloak Services 26.5.0-26.5.1 - Unauthorized Sensitive Attribute Disclosure via UnmanagedAttributes Endpoint
Feb 02, 2026
CVSS 2.7
EPSS 0.00
CVE-2025-14083
LOW
Keycloak - Improper Access Control in Admin REST API
Jan 21, 2026
CVSS 2.7
EPSS 0.00
CVE-2025-14559
MEDIUM
Keycloak Services 26.5.0-26.5.1 - Unauthorized Token Issuance via Token Exchange Flow
Jan 21, 2026
CVSS 6.5
EPSS 0.00
CVE-2025-11419
HIGH
Keycloak < 26.0.16 - Unauthenticated Denial of Service via TLS 1.2 Client-Initiated Renegotiation
Dec 23, 2025
CVSS 7.5
EPSS 0.00
CVE-2025-14082
LOW
Keycloak < 26.5.0 - Unauthenticated Sensitive Role Metadata Exposure via Admin REST API
Dec 10, 2025
CVSS 2.7
EPSS 0.00
CVE-2025-13467
MEDIUM
Keycloak LDAP Federation < 26.4.6 - Authenticated Deserialization of Untrusted Data via LDAP Server Configuration
Nov 25, 2025
CVSS 5.5
EPSS 0.00
CVE-2025-11538
MEDIUM
Keycloak < 26.4.4 - Remote Code Execution via Debug Mode JDWP Port Binding
Nov 13, 2025
CVSS 6.8
EPSS 0.00
CVE-2025-12390
MEDIUM
Keycloak < 26.0.0 - Session Fixation via Incomplete Session Cleanup
Oct 28, 2025
CVSS 6.0
EPSS 0.00
CVE-2025-10939
LOW
Keycloak < 26.4.4 - Unauthenticated Admin Path Access via Proxy Path Normalization Bypass
Oct 28, 2025
CVSS 3.7
EPSS 0.00
CVE-2025-12110
MEDIUM
Keycloak < 26.4.3 - Insufficient Session Expiration via Offline Access Scope Removal
Oct 23, 2025
CVSS 5.4
EPSS 0.00
CVE-2025-11429
MEDIUM
Keycloak < 26.4.1 - Insufficient Session Expiration via Remember Me Setting
Oct 23, 2025
CVSS 5.4
EPSS 0.00
CVE-2025-10044
MEDIUM
Keycloak < 26.2.9 - Phishing via Unsanitized Error Description Parameter
Sep 05, 2025
CVSS 4.3
EPSS 0.00
CVE-2025-9162
MEDIUM
KeycloakRealmImport - Code Injection
Aug 21, 2025
CVSS 4.9
EPSS 0.00
CVE-2025-8419
MEDIUM
Keycloak < 26.2.8 - SMTP Injection via Email Registration
Aug 06, 2025
CVSS 5.3
EPSS 0.00
CVE-2025-7784
MEDIUM
Red Hat build of Keycloak - Privilege Escalation via Fine-Grained Admin Permissions
Jul 18, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-7365
HIGH
Keycloak - Authenticated Account Takeover via Identity Provider Login Email Verification
Jul 10, 2025
CVSS 7.1
EPSS 0.00
Products
keycloak-services 74
keycloak-core 48
keycloak-parent 25
keycloak-quarkus-server 9
keycloak-server-spi-private 5
keycloak-ldap-federation 4
keycloak-saml-core 4
keycloak-model-jpa 3
keycloak-saml-adapter-core 3
keycloak-model-infinispan 2
keycloak-quarkus-dist 2
keycloak-account-ui 1
keycloak-adapter-core 1
keycloak-admin-ui 1
keycloak-authz-client 1
keycloak-broker-saml 1
keycloak-common 1
keycloak-js-admin-client 1
keycloak-model-storage-services 1
keycloak-oidc-client-adapter-pom 1
Quick Filters