CVE-2026-17614
- EPSS 0.85%
- Veröffentlicht 04.08.2026 02:12:04
- Zuletzt bearbeitet 06.08.2026 15:37:22
A path traversal flaw was found in WildFly's domain mode implementation. The LocalFileRepository.getFile() and getConfigurationFile() methods in wildfly-core/deployment-repository do not validate that the resolved file path remains within the...
CVE-2026-18573
- EPSS 0.22%
- Veröffentlicht 02.08.2026 05:28:43
- Zuletzt bearbeitet 10.08.2026 14:40:21
A flaw was found in the keycloak-services component of Keycloak, which is used for managing authentication and authorization flows. The issue occurs when a realm administrator configures client policies to enforce specific authentication requirements...
CVE-2026-18209
- EPSS 0.19%
- Veröffentlicht 31.07.2026 07:08:31
- Zuletzt bearbeitet 07.08.2026 14:35:42
A flaw was found in the keycloak-services component of Keycloak, which handles OpenID Connect (OIDC) authentication flows. The issue occurs because the security check designed to prevent HTTP parameter pollution only inspects the query portion of a r...
CVE-2026-16103
- EPSS 0.2%
- Veröffentlicht 17.07.2026 16:43:50
- Zuletzt bearbeitet 06.08.2026 16:31:55
A flaw was found in the keycloak-services component of Keycloak. This issue is an incomplete fix for CVE-2026-9798, where brute-force protection checks were added to the Client-Initiated Backchannel Authentication (CIBA) initiation handler but were o...
CVE-2026-14614
- EPSS 0.19%
- Veröffentlicht 03.07.2026 15:33:00
- Zuletzt bearbeitet 11.08.2026 15:06:15
A flaw was found in the ClientResource component of Keycloak's admin services when Fine-Grained Admin Permissions (FGAP) v2 is enabled. This issue allows a delegated administrator, who should only have limited control over specific clients, to attach...
CVE-2026-11800
- EPSS 0.18%
- Veröffentlicht 25.06.2026 20:57:05
- Zuletzt bearbeitet 15.07.2026 02:18:03
A flaw was found in Keycloak. This JWT algorithm confusion vulnerability in the JWT Authorization Grant flow allows an attacker with valid client credentials to bypass signature verification. By forging an assertion, the attacker can create unauthori...
CVE-2026-28367
- EPSS 0.71%
- Veröffentlicht 27.03.2026 16:13:05
- Zuletzt bearbeitet 29.06.2026 10:16:30
A flaw was found in Undertow. A remote attacker can exploit this vulnerability by sending `\r\r\r` as a header block terminator. This can be used for request smuggling with certain proxy servers, such as older versions of Apache Traffic Server and Go...
CVE-2026-28369
- EPSS 0.68%
- Veröffentlicht 27.03.2026 16:13:05
- Zuletzt bearbeitet 22.07.2026 06:16:33
A flaw was found in Undertow. When Undertow receives an HTTP request where the first header line starts with one or more spaces, it incorrectly processes the request by stripping these leading spaces. This behavior, which violates HTTP standards, can...
CVE-2026-28368
- EPSS 0.7%
- Veröffentlicht 27.03.2026 16:13:03
- Zuletzt bearbeitet 29.06.2026 10:16:31
A flaw was found in Undertow. This vulnerability allows a remote attacker to construct specially crafted requests where header names are parsed differently by Undertow compared to upstream proxies. This discrepancy in header interpretation can be exp...
CVE-2026-3121
- EPSS 0.47%
- Veröffentlicht 26.03.2026 19:13:26
- Zuletzt bearbeitet 02.04.2026 14:16:31
A flaw was found in Keycloak. An administrator with `manage-clients` permission can exploit a misconfiguration where this permission is equivalent to `manage-permissions`. This allows the administrator to escalate privileges and gain control over rol...