CVE-2026-79651
- EPSS 0.62%
- Veröffentlicht 16.09.2026 14:55:09
- Zuletzt bearbeitet 16.09.2026 19:42:43
A flaw was found in the theme localization endpoints of the keycloak-services component, which is the core service responsible for authentication flows and theme management in Keycloak. The issue occurs because the system accepts arbitrary locale tag...
CVE-2026-74909
- EPSS 0.89%
- Veröffentlicht 16.09.2026 14:54:47
- Zuletzt bearbeitet 18.09.2026 18:17:12
Keycloak provides a policy enforcer to protect applications by matching incoming web requests against defined security policies. A flaw was found where the enforcer fails to correctly normalize web addresses that contain special encoded characters, s...
CVE-2026-18212
- EPSS 0.52%
- Veröffentlicht 16.09.2026 14:54:15
- Zuletzt bearbeitet 16.09.2026 19:42:43
A flaw was found in the SAML Redirect Binding implementation of Keycloak, an open-source identity and access management solution. The issue occurs because the custom DEFLATE compression and decompression helpers fail to release native zlib memory aft...
CVE-2026-92358
- EPSS 0.28%
- Veröffentlicht 16.09.2026 05:50:26
- Zuletzt bearbeitet 17.09.2026 16:18:32
A flaw was found in the first broker login flow of Keycloak. When a user confirms an account-linking request from a different browser, a temporary proof is created to validate the link. However, this proof is not properly cleared after the link is es...
CVE-2026-89298
- EPSS 0.24%
- Veröffentlicht 11.09.2026 13:25:24
- Zuletzt bearbeitet 16.09.2026 19:42:43
A flaw was found in the Dynamic Client Registration service of Keycloak, an open-source identity and access management solution. The issue occurs when a user with the view-clients role accesses the client registration endpoint to retrieve client deta...
CVE-2026-88770
- EPSS 0.21%
- Veröffentlicht 10.09.2026 07:18:18
- Zuletzt bearbeitet 10.09.2026 14:50:07
A flaw was found in the Device Authorization Grant flow of Keycloak, an identity and access management solution. The issue occurs because the token redemption process fails to check if a user account is currently locked due to brute-force protection....
CVE-2026-19729
- EPSS 0.49%
- Veröffentlicht 09.09.2026 07:03:35
- Zuletzt bearbeitet 16.09.2026 19:17:10
A flaw was found in the key provider component of the keycloak-services library, which is the core engine for the Red Hat Build of Keycloak. The issue occurs because a previous fix for path probing was incomplete, allowing a realm administrator to st...
CVE-2026-82968
- EPSS 0.18%
- Veröffentlicht 02.09.2026 01:39:05
- Zuletzt bearbeitet 03.09.2026 18:12:56
A flaw was found in the first-broker-login flow of the Keycloak identity management service. When a user links a social identity provider account to their local account, the verification proof generated is not strictly bound to the specific upstream ...
CVE-2026-17615
- EPSS 0.28%
- Veröffentlicht 31.08.2026 16:15:01
- Zuletzt bearbeitet 02.10.2026 05:16:37
A flaw was found in RESTEasy's SourceProvider. This vulnerability allows an unauthenticated attacker to perform an unauthenticated remote file read. By sending a specially crafted XML body with a DOCTYPE declaration referencing external entities to a...
CVE-2026-79652
- EPSS 0.17%
- Veröffentlicht 25.08.2026 11:07:48
- Zuletzt bearbeitet 28.09.2026 23:10:00
A flaw was found in the JWT Bearer authorization grant implementation within the keycloak-services component of Red Hat Build of Keycloak. This component handles various OAuth2 and OpenID Connect grant types used for issuing access tokens. The issue ...