Org.keycloak.protocol.oidc.grants: org.keycloak.services.managers: keycloak: server-side request forgery via oidc token endpoint manipulation
Published Mar 26, 2026
3.1
LOWCVSS 3.1
EPSS 0.33%
Description
A flaw was found in Keycloak. An authenticated attacker can perform Server-Side Request Forgery (SSRF) by manipulating the `client_session_host` parameter during refresh token requests. This occurs when a Keycloak client is configured to use the `backchannel.logout.url` with the `application.session.host` placeholder. Successful exploitation allows the attacker to make HTTP requests from the Keycloak server’s network context, potentially probing internal networks or internal APIs, leading to information disclosure.
Affected products
- Vendor Red Hat Product Red Hat JBoss Enterprise Application Platform Expansion Pack Defaultaffected
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Red Hat | Red Hat Build of Keycloak | affected | |
| Red Hat | Red Hat JBoss Enterprise Application Platform 8 | affected | |
| Red Hat | Red Hat JBoss Enterprise Application Platform Expansion Pack | affected | |
| Red Hat | Red Hat Single Sign-On 7 | affected |
- n/a
- 8.0.0
- n/a
- 7.0
No data.
Red Hat build of Keycloak 26.4
rhbk/keycloak-operator-bundle:26.4.13-1
Fixed · RHSA-2026:30050
Red Hat build of Keycloak 26.4
rhbk/keycloak-rhel9-operator:26.4-19
Fixed · RHSA-2026:30050
Red Hat build of Keycloak 26.4
rhbk/keycloak-rhel9:26.4-19
Fixed · RHSA-2026:30050
Red Hat build of Keycloak 26.4.13
rhbk/keycloak-rhel9
Fixed · RHSA-2026:30049
Red Hat build of Keycloak 26.6
rhbk/keycloak-operator-bundle:26.6.3-3
Fixed · RHSA-2026:25097
Red Hat build of Keycloak 26.6
rhbk/keycloak-rhel9-operator:26.6-6
Fixed · RHSA-2026:25097
Red Hat build of Keycloak 26.6
rhbk/keycloak-rhel9:26.6-6
Fixed · RHSA-2026:25097
Red Hat build of Keycloak 26.6.3
rhbk/keycloak-rhel9
Fixed · RHSA-2026:25098
Red Hat Build of Keycloak
rhbk/keycloak-operator-bundle
Fix deferred
Red Hat Build of Keycloak
rhbk/keycloak-rhel9-operator
Fix deferred
Red Hat JBoss Enterprise Application Platform 8
keycloak-services
Fix deferred
Red Hat JBoss Enterprise Application Platform Expansion Pack
keycloak-services
Fix deferred
Red Hat Single Sign-On 7
keycloak-services
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat build of Keycloak 26.4 | rhbk/keycloak-operator-bundle:26.4.13-1 | Fixed | RHSA-2026:30050 |
| Red Hat build of Keycloak 26.4 | rhbk/keycloak-rhel9-operator:26.4-19 | Fixed | RHSA-2026:30050 |
| Red Hat build of Keycloak 26.4 | rhbk/keycloak-rhel9:26.4-19 | Fixed | RHSA-2026:30050 |
| Red Hat build of Keycloak 26.4.13 | rhbk/keycloak-rhel9 | Fixed | RHSA-2026:30049 |
| Red Hat build of Keycloak 26.6 | rhbk/keycloak-operator-bundle:26.6.3-3 | Fixed | RHSA-2026:25097 |
| Red Hat build of Keycloak 26.6 | rhbk/keycloak-rhel9-operator:26.6-6 | Fixed | RHSA-2026:25097 |
| Red Hat build of Keycloak 26.6 | rhbk/keycloak-rhel9:26.6-6 | Fixed | RHSA-2026:25097 |
| Red Hat build of Keycloak 26.6.3 | rhbk/keycloak-rhel9 | Fixed | RHSA-2026:25098 |
| Red Hat Build of Keycloak | rhbk/keycloak-operator-bundle | Fix deferred | n/a |
| Red Hat Build of Keycloak | rhbk/keycloak-rhel9-operator | Fix deferred | n/a |
| Red Hat JBoss Enterprise Application Platform 8 | keycloak-services | Fix deferred | n/a |
| Red Hat JBoss Enterprise Application Platform Expansion Pack | keycloak-services | Fix deferred | n/a |
| Red Hat Single Sign-On 7 | keycloak-services | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Red Hat statement
This flaw allows an authenticated attacker to perform Server-Side Request Forgery (SSRF) by manipulating the `client_session_host` parameter during refresh token requests. This vulnerability is exploitable when a Keycloak client is configured to use the `backchannel.logout.url` with the `application.session.host` placeholder, enabling the attacker to probe internal networks from the Keycloak server's context. Exploitation requires valid user credentials and a logout event.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (15)
- https://access.redhat.com/errata/RHSA-2026:25097 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:25098 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:30049 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:30050 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2026-4874 vdb-entryx_refsource_REDHATVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2451611 issue-trackingx_refsource_REDHATIssue TrackingVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-16142 Advisory
- https://github.com/advisories/GHSA-22rm-wp4x-v5cx Advisory
- https://github.com/keycloak/keycloak/commit/00dd0dd716c4319d3bac3eb2f2ac22d2a94f79fd
- https://github.com/keycloak/keycloak/commit/63de0efd351a7a684212a042a12271908f63f0ee
- https://github.com/keycloak/keycloak/issues/47935
- https://github.com/keycloak/keycloak/pull/49682
- https://github.com/keycloak/keycloak/pull/49685
- https://nvd.nist.gov/vuln/detail/CVE-2026-4874
- https://www.cve.org/CVERecord?id=CVE-2026-4874
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub