Redhat

Build Of Keycloak

112 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.14%
  • Veröffentlicht 06.08.2026 05:33:17
  • Zuletzt bearbeitet 10.08.2026 19:15:58

A flaw was found in the SAML broker component of Keycloak, an identity and access management solution. When configured as a SAML broker using the IdP-Initiated flow, Keycloak fails to enforce the OneTimeUse condition in SAML assertions. This allows a...

  • EPSS 0.35%
  • Veröffentlicht 05.08.2026 15:09:23
  • Zuletzt bearbeitet 10.08.2026 19:23:37

A flaw was found in Keycloak's Dynamic Client Registration (DCR) security policy management. The "Allowed Protocol Mapper Types" policy, which restricts which types of data mappers a client can use, fails to re-validate the mapper type during a clien...

  • EPSS 0.2%
  • Veröffentlicht 05.08.2026 15:00:39
  • Zuletzt bearbeitet 10.08.2026 19:21:47

A flaw was found in the SAML broker component of Keycloak, which is used to manage identity federation and user authentication. The issue occurs because the IdP-initiated Single Sign-On endpoint fails to check if a provider is restricted to account l...

  • EPSS 0.31%
  • Veröffentlicht 05.08.2026 13:50:57
  • Zuletzt bearbeitet 10.08.2026 18:17:35

A flaw was found in the user-event metrics recording of Keycloak. When metrics are enabled, the system records raw error messages from failed account operations as Prometheus metric labels. Because these error messages can include user-supplied input...

  • EPSS 0.18%
  • Veröffentlicht 05.08.2026 13:50:54
  • Zuletzt bearbeitet 10.08.2026 18:37:16

A flaw was found in the LDAP storage provider of Keycloak, which is used to federate user identities from external directories. The issue occurs when a delegated administrator performs a search using a specific LDAP entry Distinguished Name (DN). Due...

  • EPSS 0.25%
  • Veröffentlicht 05.08.2026 13:50:50
  • Zuletzt bearbeitet 20.08.2026 11:16:20

A flaw was found in the Dynamic Client Registration (DCR) component of Keycloak, an identity and access management solution. The default DCR policy fails to properly validate the claim path for User Property mappers, allowing them to write values to ...

  • EPSS 0.29%
  • Veröffentlicht 05.08.2026 13:50:03
  • Zuletzt bearbeitet 20.08.2026 11:16:20

A flaw was found in Keycloak's Authorization Services. The component responsible for matching request paths to security policies (PathMatcher) does not properly normalize URIs before comparison. By adding extra characters like a trailing slash or mat...

  • EPSS 0.15%
  • Veröffentlicht 05.08.2026 13:44:09
  • Zuletzt bearbeitet 10.08.2026 18:52:14

A flaw was found in the SAML metadata import functionality of the keycloak-services component, which is the core engine for identity brokering in Red Hat Build of Keycloak. When importing identity provider metadata that lacks specific usage attribute...

  • EPSS 0.16%
  • Veröffentlicht 04.08.2026 05:13:08
  • Zuletzt bearbeitet 10.08.2026 19:06:53

A flaw was found in the backchannel logout endpoint of the keycloak-services component, which is part of the Red Hat Build of Keycloak. This component handles authentication and session management for applications. The issue occurs when an OIDC ident...

  • EPSS 0.22%
  • Veröffentlicht 02.08.2026 05:28:43
  • Zuletzt bearbeitet 10.08.2026 14:40:21

A flaw was found in the keycloak-services component of Keycloak, which is used for managing authentication and authorization flows. The issue occurs when a realm administrator configures client policies to enforce specific authentication requirements...