Back

HIGH

Keycloak: keycloak: denial of service via specially crafted saml input

Published May 19, 2026

Description

A flaw was found in Keycloak. A remote, unauthenticated attacker can send a specially crafted XML input to the Security Assertion Markup Language (SAML) endpoint. This malicious input can cause high CPU usage and worker thread starvation, leading to a Denial of Service (DoS) where the server becomes unavailable.

Affected products

Remediation

Vendor solution

To mitigate this vulnerability, restrict network access to the Keycloak SAML endpoint to trusted networks and clients. Implement firewall rules to limit inbound connections to the Keycloak service port (e.g., 8080) from untrusted sources. If the SAML protocol is not required for your deployment, consider disabling it to eliminate the attack surface. Applying these network restrictions or configuration changes may necessitate a restart or reload of the Keycloak service, which could temporarily affect its availability.

Red Hat statement

This is a High severity denial of service vulnerability in Keycloak. An unauthenticated attacker with network access can send specially crafted XML input to the SAML endpoint, causing high CPU utilization and worker thread exhaustion, which renders the Keycloak server unavailable. This directly impacts the availability of Keycloak instances where the SAML protocol is enabled.

Red Hat mitigation

To mitigate this vulnerability, restrict network access to the Keycloak SAML endpoint to trusted networks and clients. Implement firewall rules to limit inbound connections to the Keycloak service port (e.g., 8080) from untrusted sources. If the SAML protocol is not required for your deployment, consider disabling it to eliminate the attack surface. Applying these network restrictions or configuration changes may necessitate a restart or reload of the Keycloak service, which could temporarily affect its availability.

Weaknesses (1)

References (19)

Change history (1)
  1. EUVD
    • Updated

      changed from Oct 6, 2026 to Oct 6, 2026

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner redhat
Published May 19, 2026
Updated Oct 6, 2026
Reserved Apr 28, 2026

CISA Vulnrichment

Updated May 19, 2026

NVD

Status Modified
Modified Oct 6, 2026

Red Hat

Severity Important
Public date May 19, 2026
Bugzilla 2476526

ENISA EUVD

Assigner redhat
Published May 19, 2026
Updated Oct 6, 2026