Skip to main content

Vendor/product archive

redhat / keycloak CVEs

Beta · best-effort

98 CVEs tagged to redhat / keycloak6 Critical, 28 High, 56 Medium, 8 Low, 0 Unrated.

CVE-2026-3047

Published Mar 5, 2026

A flaw was found in org.keycloak.broker.saml. When a disabled Security Assertion Markup Language (SAML) client is configured as an Identity Provider (IdP)-initiated broker landing…

CVSS 8.8 · High
evidence mentions
7
Buzz score
32.3
Vendor/product tagsBeta · best-effort

CVE-2025-12150

Published Feb 27, 2026

A flaw was found in Keycloak’s WebAuthn registration component. This vulnerability allows an attacker to bypass the configured attestation policy and register untrusted or forged…

CVSS 3.1 · Low
evidence mentions
7
Buzz score
32.3
Vendor/product tagsBeta · best-effort

CVE-2026-0871

Published Feb 27, 2026

A flaw was found in Keycloak. An administrator with `manage-users` permission can bypass the "Only administrators can view" setting for unmanaged attributes, allowing them to modi…

CVSS 4.9 · Medium
evidence mentions
4
Buzz score
26.1
Vendor/product tagsBeta · best-effort

CVE-2025-8419

Published Aug 6, 2025

A vulnerability was found in Keycloak-services. Special characters used during e-mail registration may perform SMTP Injection and unexpectedly send short unwanted e-mails. The ema…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-7365

Published Jul 10, 2025

A flaw was found in Keycloak. When an authenticated attacker attempts to merge accounts with another existing account during an identity provider (IdP) login, the attacker will su…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-5416

Published Jun 20, 2025

A vulnerability has been identified in Keycloak that could lead to unauthorized information disclosure. While it requires an already authenticated user, the /admin/serverinfo endp…

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-6841

Published Sep 10, 2024

A denial of service vulnerability was found in keycloak where the amount of attributes per object is not limited,an attacker by sending repeated HTTP requests could cause a resour…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-7260

Published Sep 9, 2024

An open redirect vulnerability was found in Keycloak. A specially crafted URL can be constructed where the referrer and referrer_uri parameters are made to trick a user to visit a…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-4629

Published Sep 3, 2024

A vulnerability was found in Keycloak. This flaw allows attackers to bypass brute force protection by exploiting the timing of login attempts. By initiating multiple login request…

CVSS 6.5 · Medium

CVE-2023-6787

Published Apr 25, 2024

A flaw was found in Keycloak that occurs from an error in the re-authentication mechanism within org.keycloak.authentication. This flaw allows hijacking an active Keycloak session…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-1722

Published Feb 29, 2024

A flaw was found in Keycloak. In certain conditions, this issue may allow a remote unauthenticated attacker to block other accounts from logging in.

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-0560

Published Feb 28, 2024

A vulnerability was found in 3Scale, when used with Keycloak 15 (or RHSSO 7.5.0) and superiors. When the auth_type is use_3scale_oidc_issuer_endpoint, the Token Introspection poli…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-6291

Published Jan 26, 2024

A flaw was found in the redirect_uri validation logic in Keycloak. This issue may allow a bypass of otherwise explicitly allowed hosts. A successful attack may lead to an access t…

CVSS 7.1 · High

CVE-2023-6927

Published Dec 18, 2023

A flaw was found in Keycloak. This issue may allow an attacker to steal authorization codes or tokens from clients using a wildcard in the JARM response mode "form_post.jwt" which…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-3916

Published Sep 20, 2023

A flaw was found in the offline_access scope in Keycloak. This issue would affect users of shared computers more (especially if cookies are not cleared), due to a lack of root ses…

CVSS 6.8 · Medium

CVE-2022-1438

Published Sep 20, 2023

A flaw was found in Keycloak. Under specific circumstances, HTML entities are not sanitized during user impersonation, resulting in a Cross-site scripting (XSS) vulnerability.

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-4918

Published Sep 12, 2023

A flaw was found in the Keycloak package, more specifically org.keycloak.userprofile. When a user registers itself through registration flow, the "password" and "password-confirm"…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 98 CVEsPage 1 of 4