Redhat

Keycloak

316 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.24%
  • Veröffentlicht 19.09.2026 14:09:17
  • Zuletzt bearbeitet 22.09.2026 19:37:36

A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution. The issue occurs in the group-membership endpoints where the system fails to check if a group grants administrative privileges before allowing...

  • EPSS 0.15%
  • Veröffentlicht 19.09.2026 14:09:11
  • Zuletzt bearbeitet 22.09.2026 19:37:36

A flaw was found in the OIDC protocol implementation of Keycloak, an open-source identity and access management solution. The issue occurs during the token refresh process when the server restores requested audiences from stored client IDs. Keycloak ...

  • EPSS 0.28%
  • Veröffentlicht 18.09.2026 20:12:51
  • Zuletzt bearbeitet 22.09.2026 21:17:33

A flaw was found in Netty's HTTP/1 decoder. Incomplete validation of malformed Transfer-Encoding headers allows a remote attacker to perform HTTP request smuggling. By sending specially crafted HTTP requests, an attacker can inject arbitrary HTTP req...

  • EPSS 0.36%
  • Veröffentlicht 18.09.2026 20:12:43
  • Zuletzt bearbeitet 24.09.2026 11:17:01

A flaw was found in Netty's `netty-codec-http` component. A remote attacker could exploit this vulnerability by sending a specially crafted HTTP/1.1 chunk-size token that includes post-digit whitespace. This incorrect parsing of the chunk size can le...

  • EPSS 0.23%
  • Veröffentlicht 18.09.2026 14:44:00
  • Zuletzt bearbeitet 24.09.2026 11:17:00

A flaw was found in Netty's HTTP/1.1 decoder. This vulnerability allows a remote attacker to bypass `Transfer-Encoding` header validation by splitting the `Transfer-Encoding` field across multiple headers, with the last field containing a non-final t...

  • EPSS 0.47%
  • Veröffentlicht 18.09.2026 14:34:04
  • Zuletzt bearbeitet 22.09.2026 19:16:58

A flaw was found in Netty. A remote attacker could exploit this vulnerability by sending specially crafted HTTP/2 or HTTP/3 Extended CONNECT requests. Netty's HTTP-object conversion path incorrectly processes these requests as regular HTTP/1.1 CONNEC...

  • EPSS 0.37%
  • Veröffentlicht 18.09.2026 14:27:54
  • Zuletzt bearbeitet 22.09.2026 19:16:58

A flaw was found in Netty. A remote unauthenticated attacker can exploit a vulnerability in Netty's HTTP/1 to HTTP/2 conversion process. When an HTTP/1 request includes both an absolute-form request-target and a conflicting Host header, Netty incorre...

  • EPSS 0.4%
  • Veröffentlicht 18.09.2026 14:23:27
  • Zuletzt bearbeitet 22.09.2026 19:16:58

A flaw was found in Netty's HTTP/2 codec. When converting HTTP/1 CONNECT requests to HTTP/2, the component incorrectly uses the Host header instead of the CONNECT authority-form request-target for the tunnel authority. A remote attacker can exploit t...

  • EPSS 0.28%
  • Veröffentlicht 18.09.2026 14:19:29
  • Zuletzt bearbeitet 29.09.2026 12:17:10

A flaw was found in the DERDecoder class within wildfly-elytron-asn1. A remote attacker can exploit this resource exhaustion vulnerability by sending a specially crafted DER (Distinguished Encoding Rules) payload. The decoder attempts to allocate exc...

  • EPSS 0.38%
  • Veröffentlicht 18.09.2026 14:19:29
  • Zuletzt bearbeitet 24.09.2026 11:16:59

A flaw was found in Netty. A remote attacker could exploit this by sending a specially crafted HTTP request that includes control characters within the chunk-size line. This bypasses the intended strict validation, allowing the attacker to inject arb...