Redhat

Data Grid

48 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.47%
  • Veröffentlicht 18.09.2026 14:34:04
  • Zuletzt bearbeitet 22.09.2026 19:16:58

A flaw was found in Netty. A remote attacker could exploit this vulnerability by sending specially crafted HTTP/2 or HTTP/3 Extended CONNECT requests. Netty's HTTP-object conversion path incorrectly processes these requests as regular HTTP/1.1 CONNEC...

  • EPSS 0.52%
  • Veröffentlicht 16.09.2026 14:54:15
  • Zuletzt bearbeitet 16.09.2026 19:42:43

A flaw was found in the SAML Redirect Binding implementation of Keycloak, an open-source identity and access management solution. The issue occurs because the custom DEFLATE compression and decompression helpers fail to release native zlib memory aft...

  • EPSS 0.4%
  • Veröffentlicht 27.08.2026 16:25:29
  • Zuletzt bearbeitet 22.09.2026 16:17:49

A flaw was found in Undertow. A remote attacker could exploit this vulnerability by sending specially crafted WebSocket messages with permessage-deflate negotiated. This could lead to excessive memory consumption due to the PerMessageDeflateFunction....

Medienbericht
  • EPSS 0.31%
  • Veröffentlicht 18.08.2026 20:40:17
  • Zuletzt bearbeitet 20.08.2026 15:17:28

A flaw was found in the legacy client-initiated account-linking endpoint of Keycloak, a widely used open-source identity and access management solution. The mechanism used to protect the account-linking process from unauthorized requests relies on a ...

  • EPSS 0.25%
  • Veröffentlicht 05.08.2026 13:50:50
  • Zuletzt bearbeitet 31.08.2026 12:17:54

A flaw was found in the Dynamic Client Registration (DCR) component of Keycloak, an identity and access management solution. The default DCR policy fails to properly validate the claim path for User Property mappers, allowing them to write values to ...

  • EPSS 0.29%
  • Veröffentlicht 05.08.2026 13:50:03
  • Zuletzt bearbeitet 31.08.2026 10:16:48

A flaw was found in Keycloak's Authorization Services. The component responsible for matching request paths to security policies (PathMatcher) does not properly normalize URIs before comparison. By adding extra characters like a trailing slash or mat...

  • EPSS 0.15%
  • Veröffentlicht 05.08.2026 13:44:09
  • Zuletzt bearbeitet 10.08.2026 18:52:14

A flaw was found in the SAML metadata import functionality of the keycloak-services component, which is the core engine for identity brokering in Red Hat Build of Keycloak. When importing identity provider metadata that lacks specific usage attribute...

  • EPSS 0.18%
  • Veröffentlicht 02.08.2026 05:18:58
  • Zuletzt bearbeitet 16.09.2026 19:17:09

Keycloak provides authorization services that allow administrators to restrict access to resources based on time policies (for example, only allowing access during business hours). A flaw was discovered where a user can include a fake time value in t...

  • EPSS 0.14%
  • Veröffentlicht 02.08.2026 05:18:42
  • Zuletzt bearbeitet 16.09.2026 19:17:09

A flaw was found in the full-scope-disabled client-policy executor within the keycloak-services component. This component is responsible for enforcing security policies during client registration and configuration in Red Hat Build of Keycloak. The is...

  • EPSS 0.19%
  • Veröffentlicht 31.07.2026 07:08:31
  • Zuletzt bearbeitet 16.09.2026 19:17:08

A flaw was found in the keycloak-services component of Keycloak, which handles OpenID Connect (OIDC) authentication flows. The issue occurs because the security check designed to prevent HTTP parameter pollution only inspects the query portion of a r...