Redhat

Keycloak

316 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.37%
  • Veröffentlicht 18.09.2026 14:18:11
  • Zuletzt bearbeitet 22.09.2026 17:17:30

A flaw was found in Netty RtspDecoder. The `RtspMethods.valueOf()` function incorrectly strips trailing control bytes from method tokens in Real-Time Streaming Protocol (RTSP) requests. A remote attacker can exploit this by sending a specially crafte...

  • EPSS 0.43%
  • Veröffentlicht 18.09.2026 14:13:32
  • Zuletzt bearbeitet 22.09.2026 17:17:30

A flaw was found in Netty. A reference-count leak in the HAProxy PROXY-v2 message decoder allows a remote, unauthenticated attacker to send specially crafted PROXY-protocol v2 headers. This can lead to memory exhaustion, resulting in a Denial of Serv...

  • EPSS 0.53%
  • Veröffentlicht 18.09.2026 14:09:01
  • Zuletzt bearbeitet 22.09.2026 23:17:08

A flaw was found in Netty's WebSocketServerExtensionHandler. A remote, unauthenticated attacker can exploit this vulnerability by using HTTP/1.1 pipelining to send requests faster than the application can respond. This leads to an unbounded growth of...

  • EPSS 0.3%
  • Veröffentlicht 18.09.2026 12:49:03
  • Zuletzt bearbeitet 29.09.2026 21:19:38

A flaw was found in Netty's HTTP/2 HpackEncoder. A remote attacker can exploit this by sending HTTP/2 SETTINGS frames with a very large MAX_HEADER_TABLE_SIZE. This causes the HpackEncoder to store an excessive number of unique headers, leading to inc...

  • EPSS 0.44%
  • Veröffentlicht 18.09.2026 12:43:26
  • Zuletzt bearbeitet 22.09.2026 19:16:57

A flaw was found in Netty's HttpServerCodec. A remote, unauthenticated attacker can exploit this vulnerability by pipelining HTTP/1.1 requests on a single connection and withholding reads. This action causes the methodOverflowQueue to grow without li...

  • EPSS 0.46%
  • Veröffentlicht 18.09.2026 11:47:52
  • Zuletzt bearbeitet 22.09.2026 23:17:07

A flaw was found in Netty. SpdySessionHandler accepts an unlimited number of concurrent remote-initiated streams because localConcurrentStreams defaults to Integer.MAX_VALUE and the handler provides no API to change it. A remote peer can open a SPDY ...

  • EPSS 0.56%
  • Veröffentlicht 18.09.2026 07:13:39
  • Zuletzt bearbeitet 18.09.2026 19:06:08

A flaw was found in RESTEasy's IIOImageProvider, which decodes attacker-supplied image request bodies without enforcing any limit on the declared image dimensions or pixel count. A remote, unauthenticated attacker can send a small crafted image decla...

  • EPSS 0.4%
  • Veröffentlicht 17.09.2026 18:47:34
  • Zuletzt bearbeitet 22.09.2026 19:16:56

A flaw was found in Keycloak. When deployed in stateless mode with MySQL or MariaDB, a mismatch in row-count semantics between the database driver and Keycloak's application logic allows an attacker to bypass replay protection. This vulnerability ena...

  • EPSS 0.51%
  • Veröffentlicht 16.09.2026 15:46:43
  • Zuletzt bearbeitet 16.09.2026 19:42:43

A flaw was found in the first-broker-login flow of the keycloak-services component. This component handles the initial authentication and account linking when a user logs in via an external identity provider. The issue allows an attacker to register ...

  • EPSS 0.45%
  • Veröffentlicht 16.09.2026 15:46:13
  • Zuletzt bearbeitet 16.09.2026 19:42:43

Keycloak is an open-source identity and access management solution. A vulnerability was discovered where a user with the impersonation role can impersonate a realm administrator. This allows the attacker to gain full administrative control over the r...