Redhat

Single Sign-on

134 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.23%
  • Veröffentlicht 21.09.2026 06:03:37
  • Zuletzt bearbeitet 22.09.2026 19:37:36

A flaw was found in the Authorization Services component of Keycloak, an open-source identity and access management solution. The issue occurs in the policy evaluation endpoint, which is used by administrators to test how access policies apply to spe...

  • EPSS 0.24%
  • Veröffentlicht 19.09.2026 14:09:17
  • Zuletzt bearbeitet 22.09.2026 19:37:36

A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution. The issue occurs in the group-membership endpoints where the system fails to check if a group grants administrative privileges before allowing...

  • EPSS 0.41%
  • Veröffentlicht 18.09.2026 13:44:20
  • Zuletzt bearbeitet 22.09.2026 15:17:23

A flaw was found in the Netty STOMP codec. A remote attacker could send a specially crafted STOMP frame with a content-length header exceeding the maximum integer value. This integer truncation vulnerability could lead to an infinite decode loop, cau...

  • EPSS 0.18%
  • Veröffentlicht 18.09.2026 10:02:36
  • Zuletzt bearbeitet 25.09.2026 09:17:07

A flaw was found in io.netty/netty-codec-memcache. The Memcache binary protocol codec incorrectly reads `keyLength` and `extrasLength` as signed Java types instead of unsigned, as specified by the protocol. A malicious Memcache server can exploit thi...

  • EPSS 0.52%
  • Veröffentlicht 16.09.2026 14:54:15
  • Zuletzt bearbeitet 16.09.2026 19:42:43

A flaw was found in the SAML Redirect Binding implementation of Keycloak, an open-source identity and access management solution. The issue occurs because the custom DEFLATE compression and decompression helpers fail to release native zlib memory aft...

Medienbericht
  • EPSS 0.31%
  • Veröffentlicht 18.08.2026 20:40:17
  • Zuletzt bearbeitet 20.08.2026 15:17:28

A flaw was found in the legacy client-initiated account-linking endpoint of Keycloak, a widely used open-source identity and access management solution. The mechanism used to protect the account-linking process from unauthorized requests relies on a ...

  • EPSS 0.25%
  • Veröffentlicht 05.08.2026 13:50:50
  • Zuletzt bearbeitet 31.08.2026 12:17:54

A flaw was found in the Dynamic Client Registration (DCR) component of Keycloak, an identity and access management solution. The default DCR policy fails to properly validate the claim path for User Property mappers, allowing them to write values to ...

  • EPSS 0.29%
  • Veröffentlicht 05.08.2026 13:50:03
  • Zuletzt bearbeitet 31.08.2026 10:16:48

A flaw was found in Keycloak's Authorization Services. The component responsible for matching request paths to security policies (PathMatcher) does not properly normalize URIs before comparison. By adding extra characters like a trailing slash or mat...

  • EPSS 0.15%
  • Veröffentlicht 05.08.2026 13:44:09
  • Zuletzt bearbeitet 10.08.2026 18:52:14

A flaw was found in the SAML metadata import functionality of the keycloak-services component, which is the core engine for identity brokering in Red Hat Build of Keycloak. When importing identity provider metadata that lacks specific usage attribute...

  • EPSS 0.18%
  • Veröffentlicht 02.08.2026 05:18:58
  • Zuletzt bearbeitet 16.09.2026 19:17:09

Keycloak provides authorization services that allow administrators to restrict access to resources based on time policies (for example, only allowing access during business hours). A flaw was discovered where a user can include a fake time value in t...