Redhat

Keycloak

316 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.29%
  • Veröffentlicht 05.08.2026 13:50:03
  • Zuletzt bearbeitet 31.08.2026 10:16:48

A flaw was found in Keycloak's Authorization Services. The component responsible for matching request paths to security policies (PathMatcher) does not properly normalize URIs before comparison. By adding extra characters like a trailing slash or mat...

  • EPSS 0.15%
  • Veröffentlicht 05.08.2026 13:44:09
  • Zuletzt bearbeitet 10.08.2026 18:52:14

A flaw was found in the SAML metadata import functionality of the keycloak-services component, which is the core engine for identity brokering in Red Hat Build of Keycloak. When importing identity provider metadata that lacks specific usage attribute...

  • EPSS 0.16%
  • Veröffentlicht 04.08.2026 05:13:08
  • Zuletzt bearbeitet 10.08.2026 19:06:53

A flaw was found in the backchannel logout endpoint of the keycloak-services component, which is part of the Red Hat Build of Keycloak. This component handles authentication and session management for applications. The issue occurs when an OIDC ident...

  • EPSS 0.22%
  • Veröffentlicht 02.08.2026 05:28:43
  • Zuletzt bearbeitet 16.09.2026 19:17:09

A flaw was found in the keycloak-services component of Keycloak, which is used for managing authentication and authorization flows. The issue occurs when a realm administrator configures client policies to enforce specific authentication requirements...

  • EPSS 0.18%
  • Veröffentlicht 02.08.2026 05:18:58
  • Zuletzt bearbeitet 16.09.2026 19:17:09

Keycloak provides authorization services that allow administrators to restrict access to resources based on time policies (for example, only allowing access during business hours). A flaw was discovered where a user can include a fake time value in t...

  • EPSS 0.25%
  • Veröffentlicht 02.08.2026 05:18:50
  • Zuletzt bearbeitet 16.09.2026 19:17:09

A flaw was found in the user creation component of Keycloak when Fine-Grained Admin Permissions V2 (FGAP V2) is enabled. This issue allows a sub-administrator with permission to create users to add those users to any group, even groups the sub-admini...

  • EPSS 0.14%
  • Veröffentlicht 02.08.2026 05:18:42
  • Zuletzt bearbeitet 16.09.2026 19:17:09

A flaw was found in the full-scope-disabled client-policy executor within the keycloak-services component. This component is responsible for enforcing security policies during client registration and configuration in Red Hat Build of Keycloak. The is...

  • EPSS 0.19%
  • Veröffentlicht 31.07.2026 07:08:31
  • Zuletzt bearbeitet 16.09.2026 19:17:08

A flaw was found in the keycloak-services component of Keycloak, which handles OpenID Connect (OIDC) authentication flows. The issue occurs because the security check designed to prevent HTTP parameter pollution only inspects the query portion of a r...

  • EPSS 0.2%
  • Veröffentlicht 31.07.2026 07:08:29
  • Zuletzt bearbeitet 07.08.2026 14:54:56

A flaw was found in the keycloak-services component of Keycloak, which provides identity and access management services. The issue occurs when a realm administrator uses a wildcard domain (like *.example.com) to restrict which hosts can register or u...

  • EPSS 0.18%
  • Veröffentlicht 31.07.2026 07:08:26
  • Zuletzt bearbeitet 07.08.2026 14:56:33

A flaw was found in the group policy evaluation logic of Keycloak, an identity and access management solution. When a group policy is set to extend permissions to child groups, the system incorrectly uses a simple text-based prefix check to verify gr...