CVE-2026-17048
- EPSS 0.24%
- Veröffentlicht 24.07.2026 13:41:09
- Zuletzt bearbeitet 19.08.2026 04:16:57
A flaw was found in the Keycloak Admin REST API, which is used to manage security realms and clients. The issue occurs when the system processes requests for rotated client secrets that are stored in a secure vault. Due to improper boundary enforceme...
CVE-2026-16104
- EPSS 0.21%
- Veröffentlicht 17.07.2026 16:43:54
- Zuletzt bearbeitet 06.08.2026 16:25:57
A flaw was found in the authentication configuration endpoint of the keycloak-services component, which is the core engine for Red Hat Build of Keycloak identity and access management. The issue occurs because the system fails to mask sensitive confi...
CVE-2026-16108
- EPSS 0.19%
- Veröffentlicht 17.07.2026 16:43:14
- Zuletzt bearbeitet 06.08.2026 16:22:19
A flaw was found in the default-groups REST endpoint and realm representation of Keycloak. This component is responsible for managing groups that are automatically assigned to new users within a realm. The issue allows a delegated administrator with ...
CVE-2026-16093
- EPSS 0.18%
- Veröffentlicht 17.07.2026 16:42:52
- Zuletzt bearbeitet 09.08.2026 15:04:53
Keycloak provides a mechanism called Client Policies to enforce security requirements on clients, such as requiring them to use signed JWTs for authentication. A flaw was discovered where this enforcement can be bypassed. An attacker with valid clien...
CVE-2026-15945
- EPSS 0.18%
- Veröffentlicht 16.07.2026 17:36:24
- Zuletzt bearbeitet 09.08.2026 14:48:50
A flaw was found in the group search functionality of the Keycloak server's administrative API. When Fine-Grained Admin Permissions (FGAP) v2 is enabled, a delegated administrator can bypass access restrictions to view parent groups they are not auth...
CVE-2026-14781
- EPSS 0.18%
- Veröffentlicht 05.07.2026 06:55:30
- Zuletzt bearbeitet 11.08.2026 01:13:00
A flaw exists in the org.keycloak.broker.oidc package where the OIDC broker incorrectly synchronizes the email_verified claim. When an OIDC identity provider is configured with trustEmail=true and the userinfo endpoint is enabled, Keycloak retrieves ...
CVE-2026-14614
- EPSS 0.19%
- Veröffentlicht 03.07.2026 15:33:00
- Zuletzt bearbeitet 11.08.2026 15:06:15
A flaw was found in the ClientResource component of Keycloak's admin services when Fine-Grained Admin Permissions (FGAP) v2 is enabled. This issue allows a delegated administrator, who should only have limited control over specific clients, to attach...
CVE-2026-28367
- EPSS 0.71%
- Veröffentlicht 27.03.2026 16:13:05
- Zuletzt bearbeitet 29.06.2026 10:16:30
A flaw was found in Undertow. A remote attacker can exploit this vulnerability by sending `\r\r\r` as a header block terminator. This can be used for request smuggling with certain proxy servers, such as older versions of Apache Traffic Server and Go...
CVE-2026-28369
- EPSS 0.68%
- Veröffentlicht 27.03.2026 16:13:05
- Zuletzt bearbeitet 22.07.2026 06:16:33
A flaw was found in Undertow. When Undertow receives an HTTP request where the first header line starts with one or more spaces, it incorrectly processes the request by stripping these leading spaces. This behavior, which violates HTTP standards, can...
CVE-2026-28368
- EPSS 0.7%
- Veröffentlicht 27.03.2026 16:13:03
- Zuletzt bearbeitet 29.06.2026 10:16:31
A flaw was found in Undertow. This vulnerability allows a remote attacker to construct specially crafted requests where header names are parsed differently by Undertow compared to upstream proxies. This discrepancy in header interpretation can be exp...