Record summary

CVE-2026-18209 has a selected CVSS score of 3.4 (low).

Description

A flaw was found in the keycloak-services component of Keycloak, which handles OpenID Connect (OIDC) authentication flows. The issue occurs because the security check designed to prevent HTTP parameter pollution only inspects the query portion of a redirect URL and ignores the fragment portion. When a client is configured with a wildcard redirect URI, an attacker can use this to inject duplicate security parameters into the login response. If a client application is not configured correctly, it might trust the attacker's injected data instead of the real security information from Keycloak, leading to session fixation or account confusion.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 31, 2026 · Source: CVE List

Affected products and versions

6
ProductSourceVersion rangeStatus

Red Hat Build of Keycloak

Browse Red Hat / Red Hat Build of Keycloakkeycloak-services

Default status: affected

CVE ListVersion data not supplied

Red Hat Build of Keycloak

Browse Red Hat / Red Hat Build of Keycloakrhbk-keycloak-rhel9/rhbk-keycloak-rhel9

Default status: affected

CVE ListVersion data not supplied

Red Hat Build of Keycloak

Browse Red Hat / Red Hat Build of Keycloakrhbk-openshift-rhel9/rhbk-openshift-rhel9

Default status: affected

CVE ListVersion data not supplied

Red Hat Data Grid 8

Browse Red Hat / Red Hat Data Grid 8keycloak-services

Default status: unaffected

CVE ListVersion data not supplied

Red Hat JBoss Enterprise Application Platform Expansion Pack

Browse Red Hat / Red Hat JBoss Enterprise Application Platform Expansion Packkeycloak-services

Default status: unaffected

CVE ListVersion data not supplied

Red Hat Single Sign-On 7

Browse Red Hat / Red Hat Single Sign-On 7keycloak-services

Default status: unaffected

CVE ListVersion data not supplied

References

3