Keycloak: keycloak: denial of service via specially crafted saml input
Published May 19, 2026
7.5
HIGHCVSS 3.1
EPSS 1.01%
Description
A flaw was found in Keycloak. A remote, unauthenticated attacker can send a specially crafted XML input to the Security Assertion Markup Language (SAML) endpoint. This malicious input can cause high CPU usage and worker thread starvation, leading to a Denial of Service (DoS) where the server becomes unavailable.
Affected products
No data.
- ≥ 26.4 · < 26.4.12
No data.
Red Hat build of Keycloak 26.2
rhbk/keycloak-operator-bundle:26.2.16-1
Fixed · RHSA-2026:19595
Red Hat build of Keycloak 26.2
rhbk/keycloak-rhel9-operator:26.2-21
Fixed · RHSA-2026:19595
Red Hat build of Keycloak 26.2
rhbk/keycloak-rhel9:26.2-21
Fixed · RHSA-2026:19595
Red Hat build of Keycloak 26.2.16
rhbk/keycloak-rhel9
Fixed · RHSA-2026:19594
Red Hat build of Keycloak 26.4
rhbk/keycloak-operator-bundle:26.4.12-1
Fixed · RHSA-2026:19597
Red Hat build of Keycloak 26.4
rhbk/keycloak-rhel9-operator:26.4-17
Fixed · RHSA-2026:19597
Red Hat build of Keycloak 26.4
rhbk/keycloak-rhel9:26.4-17
Fixed · RHSA-2026:19597
Red Hat build of Keycloak 26.4.12
rhbk/keycloak-rhel9
Fixed · RHSA-2026:19596
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat build of Keycloak 26.2 | rhbk/keycloak-operator-bundle:26.2.16-1 | Fixed | RHSA-2026:19595 |
| Red Hat build of Keycloak 26.2 | rhbk/keycloak-rhel9-operator:26.2-21 | Fixed | RHSA-2026:19595 |
| Red Hat build of Keycloak 26.2 | rhbk/keycloak-rhel9:26.2-21 | Fixed | RHSA-2026:19595 |
| Red Hat build of Keycloak 26.2.16 | rhbk/keycloak-rhel9 | Fixed | RHSA-2026:19594 |
| Red Hat build of Keycloak 26.4 | rhbk/keycloak-operator-bundle:26.4.12-1 | Fixed | RHSA-2026:19597 |
| Red Hat build of Keycloak 26.4 | rhbk/keycloak-rhel9-operator:26.4-17 | Fixed | RHSA-2026:19597 |
| Red Hat build of Keycloak 26.4 | rhbk/keycloak-rhel9:26.4-17 | Fixed | RHSA-2026:19597 |
| Red Hat build of Keycloak 26.4.12 | rhbk/keycloak-rhel9 | Fixed | RHSA-2026:19596 |
No package ranges for this CVE.
Remediation
Vendor solution
To mitigate this vulnerability, restrict network access to the Keycloak SAML endpoint to trusted networks and clients. Implement firewall rules to limit inbound connections to the Keycloak service port (e.g., 8080) from untrusted sources. If the SAML protocol is not required for your deployment, consider disabling it to eliminate the attack surface. Applying these network restrictions or configuration changes may necessitate a restart or reload of the Keycloak service, which could temporarily affect its availability.
Red Hat statement
This is a High severity denial of service vulnerability in Keycloak. An unauthenticated attacker with network access can send specially crafted XML input to the SAML endpoint, causing high CPU utilization and worker thread exhaustion, which renders the Keycloak server unavailable. This directly impacts the availability of Keycloak instances where the SAML protocol is enabled.
Red Hat mitigation
To mitigate this vulnerability, restrict network access to the Keycloak SAML endpoint to trusted networks and clients. Implement firewall rules to limit inbound connections to the Keycloak service port (e.g., 8080) from untrusted sources. If the SAML protocol is not required for your deployment, consider disabling it to eliminate the attack surface. Applying these network restrictions or configuration changes may necessitate a restart or reload of the Keycloak service, which could temporarily affect its availability.
References (19)
- https://access.redhat.com/errata/RHSA-2026:19594 vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/errata/RHSA-2026:19595 vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/errata/RHSA-2026:19596 vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/errata/RHSA-2026:19597 vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/errata/RHSA-2026:76128 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:76129 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:76130 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:76132 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:76134 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2026-7307 vdb-entryx_refsource_REDHATVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2476526 issue-trackingx_refsource_REDHATVendor AdvisoryIssue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-30883 Advisory
- https://github.com/advisories/GHSA-p5mv-gj8j-xqgf Advisory
- https://github.com/keycloak/keycloak/commit/be84d28ce4c69c038d542f11405d5ede1d61f4a9
- https://github.com/keycloak/keycloak/pull/49119
- https://github.com/keycloak/keycloak/releases/tag/26.6.2
- https://nvd.nist.gov/vuln/detail/CVE-2026-7307
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-7307.json
- https://www.cve.org/CVERecord?id=CVE-2026-7307
Change history (1)
- EUVD
Updated
changed from Oct 6, 2026 to Oct 6, 2026Oct 6, 2026 → Oct 6, 2026
CVE.org / MITRE
CISA Vulnrichment
GitHub