Redhat

Build Of Keycloak

112 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.5%
  • Veröffentlicht 18.03.2026 03:19:09
  • Zuletzt bearbeitet 03.06.2026 19:36:23

A flaw was found in Keycloak. An unauthenticated remote attacker can trigger an application level Denial of Service (DoS) by sending a highly compressed SAMLRequest through the SAML Redirect Binding. The server fails to enforce size limits during DEF...

Exploit
  • EPSS 0.42%
  • Veröffentlicht 18.03.2026 01:14:53
  • Zuletzt bearbeitet 18.08.2026 17:48:33

A flaw was found in Keycloak. A remote attacker could bypass security controls by sending a valid SAML response from an external Identity Provider (IdP) to the Keycloak SAML endpoint for IdP-initiated broker logins. This allows the attacker to comple...

  • EPSS 0.31%
  • Veröffentlicht 18.03.2026 01:14:48
  • Zuletzt bearbeitet 18.08.2026 17:49:38

A flaw was found in Keycloak. Keycloak's Security Assertion Markup Language (SAML) broker endpoint does not properly validate encrypted assertions when the overall SAML response is not signed. An attacker with a valid signed SAML assertion can exploi...

Exploit
  • EPSS 0.27%
  • Veröffentlicht 12.03.2026 10:54:31
  • Zuletzt bearbeitet 18.08.2026 16:38:20

A flaw was found in Keycloak. An authorization bypass vulnerability in the Keycloak Admin API allows any authenticated user, even those without administrative privileges, to enumerate the organization memberships of other users. This information disc...

  • EPSS 0.25%
  • Veröffentlicht 11.03.2026 16:17:24
  • Zuletzt bearbeitet 18.08.2026 16:37:56

A flaw was identified in the Account REST API of Keycloak that allows a user authenticated at a lower security level to perform sensitive actions intended only for higher-assurance sessions. Specifically, an attacker who has already obtained a victim...

  • EPSS 0.33%
  • Veröffentlicht 11.03.2026 05:36:43
  • Zuletzt bearbeitet 07.05.2026 18:30:50

A flaw was found in Keycloak. An authenticated user with the view-users role could exploit a vulnerability in the UserResource component. By accessing a specific administrative endpoint, this user could improperly retrieve user attributes that were c...

  • EPSS 0.47%
  • Veröffentlicht 05.03.2026 18:28:36
  • Zuletzt bearbeitet 15.07.2026 02:20:56

A flaw was found in org.keycloak.broker.saml. When a disabled Security Assertion Markup Language (SAML) client is configured as an Identity Provider (IdP)-initiated broker landing target, it can still complete the login process and establish a Single...

  • EPSS 0.33%
  • Veröffentlicht 05.03.2026 18:27:43
  • Zuletzt bearbeitet 17.08.2026 12:18:24

A security flaw in the IdentityBrokerService.performLogin endpoint of Keycloak allows authentication to proceed using an Identity Provider (IdP) even after it has been disabled by an administrator. An attacker who knows the IdP alias can reuse a prev...

  • EPSS 0.2%
  • Veröffentlicht 27.02.2026 08:10:15
  • Zuletzt bearbeitet 10.08.2026 03:16:39

A flaw was found in Keycloak’s WebAuthn registration component. This vulnerability allows an attacker to bypass the configured attestation policy and register untrusted or forged authenticators via submission of an attestation object with fmt: "none"...

  • EPSS 0.31%
  • Veröffentlicht 27.02.2026 07:30:26
  • Zuletzt bearbeitet 05.03.2026 02:03:32

A flaw was found in Keycloak. An administrator with `manage-users` permission can bypass the "Only administrators can view" setting for unmanaged attributes, allowing them to modify these attributes. This improper access control can lead to unauthori...