Redhat

Keycloak

266 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS -
  • Veröffentlicht 20.08.2026 15:58:24
  • Zuletzt bearbeitet 20.08.2026 16:17:18

A flaw was found in WildFly Elytron. Password hashing and verification normalize input with Unicode NFKC, which can collapse fullwidth characters to ASCII equivalents. A remote attacker can more easily guess affected passwords by using an ASCII-only ...

  • EPSS 0.31%
  • Veröffentlicht 18.08.2026 20:40:17
  • Zuletzt bearbeitet 20.08.2026 15:17:28

A flaw was found in the legacy client-initiated account-linking endpoint of Keycloak, a widely used open-source identity and access management solution. The mechanism used to protect the account-linking process from unauthorized requests relies on a ...

  • EPSS 0.39%
  • Veröffentlicht 18.08.2026 17:05:07
  • Zuletzt bearbeitet 20.08.2026 14:17:10

A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. The issue allows an unauthenticated attacker to force the password reset proc...

  • EPSS 0.25%
  • Veröffentlicht 18.08.2026 11:16:50
  • Zuletzt bearbeitet 18.08.2026 15:04:46

A flaw was found in the group policy provider of Keycloak authorization services, which is used to manage fine-grained access control to resources. The issue occurs when the system evaluates group-based policies using tokens that only contain group n...

  • EPSS 0.14%
  • Veröffentlicht 06.08.2026 05:33:17
  • Zuletzt bearbeitet 10.08.2026 19:15:58

A flaw was found in the SAML broker component of Keycloak, an identity and access management solution. When configured as a SAML broker using the IdP-Initiated flow, Keycloak fails to enforce the OneTimeUse condition in SAML assertions. This allows a...

  • EPSS 0.35%
  • Veröffentlicht 05.08.2026 15:09:23
  • Zuletzt bearbeitet 10.08.2026 19:23:37

A flaw was found in Keycloak's Dynamic Client Registration (DCR) security policy management. The "Allowed Protocol Mapper Types" policy, which restricts which types of data mappers a client can use, fails to re-validate the mapper type during a clien...

  • EPSS 0.2%
  • Veröffentlicht 05.08.2026 15:00:39
  • Zuletzt bearbeitet 10.08.2026 19:21:47

A flaw was found in the SAML broker component of Keycloak, which is used to manage identity federation and user authentication. The issue occurs because the IdP-initiated Single Sign-On endpoint fails to check if a provider is restricted to account l...

  • EPSS 0.31%
  • Veröffentlicht 05.08.2026 13:50:57
  • Zuletzt bearbeitet 10.08.2026 18:17:35

A flaw was found in the user-event metrics recording of Keycloak. When metrics are enabled, the system records raw error messages from failed account operations as Prometheus metric labels. Because these error messages can include user-supplied input...

  • EPSS 0.18%
  • Veröffentlicht 05.08.2026 13:50:54
  • Zuletzt bearbeitet 10.08.2026 18:37:16

A flaw was found in the LDAP storage provider of Keycloak, which is used to federate user identities from external directories. The issue occurs when a delegated administrator performs a search using a specific LDAP entry Distinguished Name (DN). Due...

  • EPSS 0.25%
  • Veröffentlicht 05.08.2026 13:50:50
  • Zuletzt bearbeitet 20.08.2026 11:16:20

A flaw was found in the Dynamic Client Registration (DCR) component of Keycloak, an identity and access management solution. The default DCR policy fails to properly validate the claim path for User Property mappers, allowing them to write values to ...