Skip to main content

Vendor/product archive

redhat / single_sign-on CVEs

Beta · best-effort

111 CVEs tagged to redhat / single_sign-on6 Critical, 48 High, 50 Medium, 7 Low, 0 Unrated.

CVE-2026-28369

Published Mar 27, 2026

A flaw was found in Undertow. When Undertow receives an HTTP request where the first header line starts with one or more spaces, it incorrectly processes the request by stripping…

CVSS 8.7 · High
evidence mentions
4
Buzz score
22.6

CVE-2026-28368

Published Mar 27, 2026

A flaw was found in Undertow. This vulnerability allows a remote attacker to construct specially crafted requests where header names are parsed differently by Undertow compared to…

CVSS 8.7 · High
evidence mentions
4
Buzz score
22.6

CVE-2026-28367

Published Mar 27, 2026

A flaw was found in Undertow. A remote attacker can exploit this vulnerability by sending `\r\r\r` as a header block terminator. This can be used for request smuggling with certai…

CVSS 8.7 · High
evidence mentions
4
Buzz score
22.6

CVE-2025-12543

Published Jan 7, 2026

A flaw was found in the Undertow HTTP server core, which is used in WildFly, JBoss EAP, and other Java applications. The Undertow library fails to properly validate the Host heade…

CVSS 9.6 · Critical
evidence mentions
16
Buzz score
39.8

CVE-2025-9784

Published Sep 2, 2025

A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, referred to as the "MadeYouReset"…

CVSS 7.5 · High
evidence mentions
20
Buzz score
46.0

CVE-2024-8883

Published Sep 19, 2024

A misconfiguration flaw was found in Keycloak. This issue can allow an attacker to redirect users to an arbitrary URL if a 'Valid Redirect URI' is set to http://localhost or http:…

CVSS 6.1 · Medium
evidence mentions
17
Buzz score
36.9

CVE-2023-6841

Published Sep 10, 2024

A denial of service vulnerability was found in keycloak where the amount of attributes per object is not limited,an attacker by sending repeated HTTP requests could cause a resour…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-4629

Published Sep 3, 2024

A vulnerability was found in Keycloak. This flaw allows attackers to bypass brute force protection by exploiting the timing of login attempts. By initiating multiple login request…

CVSS 6.5 · Medium

CVE-2024-7885

Published Aug 21, 2024

A vulnerability was found in Undertow where the ProxyProtocolReadListener reuses the same StringBuilder instance across multiple requests. This issue occurs when the parseProxyPro…

CVSS 7.5 · High
evidence mentions
13
Buzz score
34.4

CVE-2024-1132

Published Apr 17, 2024

A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. This issue could allow an attacker to construct a malicious request to bypass valida…

CVSS 8.1 · High
evidence mentions
14
Buzz score
33.6

CVE-2024-1635

Published Feb 19, 2024

A vulnerability was found in Undertow. This vulnerability impacts a server that supports the wildfly-http-client protocol. Whenever a malicious user opens and closes a connection…

CVSS 7.5 · High
evidence mentions
16
Buzz score
36.3

CVE-2023-6291

Published Jan 26, 2024

A flaw was found in the redirect_uri validation logic in Keycloak. This issue may allow a bypass of otherwise explicitly allowed hosts. A successful attack may lead to an access t…

CVSS 7.1 · High

CVE-2023-2585

Published Dec 21, 2023

Keycloak's device authorization grant does not correctly validate the device code and client ID. An attacker client could abuse the missing validation to spoof a client consent re…

CVSS 3.5 · Low

CVE-2023-6927

Published Dec 18, 2023

A flaw was found in Keycloak. This issue may allow an attacker to steal authorization codes or tokens from clients using a wildcard in the JARM response mode "form_post.jwt" which…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 111 CVEsPage 1 of 5