CVE-2026-93560
- EPSS 0.41%
- Veröffentlicht 18.09.2026 13:44:20
- Zuletzt bearbeitet 22.09.2026 15:17:23
A flaw was found in the Netty STOMP codec. A remote attacker could send a specially crafted STOMP frame with a content-length header exceeding the maximum integer value. This integer truncation vulnerability could lead to an infinite decode loop, cau...
CVE-2026-93561
- EPSS 0.18%
- Veröffentlicht 18.09.2026 10:02:36
- Zuletzt bearbeitet 25.09.2026 09:17:07
A flaw was found in io.netty/netty-codec-memcache. The Memcache binary protocol codec incorrectly reads `keyLength` and `extrasLength` as signed Java types instead of unsigned, as specified by the protocol. A malicious Memcache server can exploit thi...
CVE-2026-17614
- EPSS 0.85%
- Veröffentlicht 04.08.2026 02:12:04
- Zuletzt bearbeitet 06.08.2026 15:37:22
A path traversal flaw was found in WildFly's domain mode implementation. The LocalFileRepository.getFile() and getConfigurationFile() methods in wildfly-core/deployment-repository do not validate that the resolved file path remains within the...
CVE-2026-18573
- EPSS 0.22%
- Veröffentlicht 02.08.2026 05:28:43
- Zuletzt bearbeitet 16.09.2026 19:17:09
A flaw was found in the keycloak-services component of Keycloak, which is used for managing authentication and authorization flows. The issue occurs when a realm administrator configures client policies to enforce specific authentication requirements...
CVE-2026-18209
- EPSS 0.19%
- Veröffentlicht 31.07.2026 07:08:31
- Zuletzt bearbeitet 16.09.2026 19:17:08
A flaw was found in the keycloak-services component of Keycloak, which handles OpenID Connect (OIDC) authentication flows. The issue occurs because the security check designed to prevent HTTP parameter pollution only inspects the query portion of a r...
CVE-2026-16103
- EPSS 0.2%
- Veröffentlicht 17.07.2026 16:43:50
- Zuletzt bearbeitet 31.08.2026 12:17:55
A flaw was found in the keycloak-services component of Keycloak. This issue is an incomplete fix for CVE-2026-9798, where brute-force protection checks were added to the Client-Initiated Backchannel Authentication (CIBA) initiation handler but were o...
CVE-2026-14614
- EPSS 0.19%
- Veröffentlicht 03.07.2026 15:33:00
- Zuletzt bearbeitet 11.08.2026 15:06:15
A flaw was found in the ClientResource component of Keycloak's admin services when Fine-Grained Admin Permissions (FGAP) v2 is enabled. This issue allows a delegated administrator, who should only have limited control over specific clients, to attach...
CVE-2026-11800
- EPSS 0.18%
- Veröffentlicht 25.06.2026 20:57:05
- Zuletzt bearbeitet 15.07.2026 02:18:03
A flaw was found in Keycloak. This JWT algorithm confusion vulnerability in the JWT Authorization Grant flow allows an attacker with valid client credentials to bypass signature verification. By forging an assertion, the attacker can create unauthori...
CVE-2026-28367
- EPSS 0.71%
- Veröffentlicht 27.03.2026 16:13:05
- Zuletzt bearbeitet 21.09.2026 14:17:15
A flaw was found in Undertow. A remote attacker can exploit this vulnerability by sending `\r\r\r` as a header block terminator. This can be used for request smuggling with certain proxy servers, such as older versions of Apache Traffic Server and Go...
CVE-2026-28369
- EPSS 0.68%
- Veröffentlicht 27.03.2026 16:13:05
- Zuletzt bearbeitet 21.09.2026 14:17:15
A flaw was found in Undertow. When Undertow receives an HTTP request where the first header line starts with one or more spaces, it incorrectly processes the request by stripping these leading spaces. This behavior, which violates HTTP standards, can...