Keycloak: keycloak: denial of service via malformed ldap password policy response
Published May 28, 2026
4.9
MEDIUMCVSS 3.1
EPSS 0.90%
Description
A flaw was found in Keycloak. A remote attacker with high privileges, such as a realm administrator configuring a malicious Lightweight Directory Access Protocol (LDAP) server or an attacker compromising an upstream LDAP server, could exploit this vulnerability. By sending a malformed LDAP password policy response during a password authentication request, the attacker can trigger an OutOfMemoryError. This causes the Keycloak Java Virtual Machine (JVM) to terminate, leading to a denial of service (DoS) for all realms on the affected node.
Affected products
No data.
- n/a
No data.
Red Hat build of Keycloak 26.4
rhbk/keycloak-operator-bundle:26.4.13-1
Fixed · RHSA-2026:30050
Red Hat build of Keycloak 26.4
rhbk/keycloak-rhel9-operator:26.4-19
Fixed · RHSA-2026:30050
Red Hat build of Keycloak 26.4
rhbk/keycloak-rhel9:26.4-19
Fixed · RHSA-2026:30050
Red Hat build of Keycloak 26.4.13
rhbk/keycloak-rhel9
Fixed · RHSA-2026:30049
Red Hat build of Keycloak 26.6
rhbk/keycloak-operator-bundle:26.6.3-3
Fixed · RHSA-2026:25097
Red Hat build of Keycloak 26.6
rhbk/keycloak-rhel9-operator:26.6-6
Fixed · RHSA-2026:25097
Red Hat build of Keycloak 26.6
rhbk/keycloak-rhel9:26.6-6
Fixed · RHSA-2026:25097
Red Hat build of Keycloak 26.6.3
rhbk/keycloak-rhel9
Fixed · RHSA-2026:25098
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat build of Keycloak 26.4 | rhbk/keycloak-operator-bundle:26.4.13-1 | Fixed | RHSA-2026:30050 |
| Red Hat build of Keycloak 26.4 | rhbk/keycloak-rhel9-operator:26.4-19 | Fixed | RHSA-2026:30050 |
| Red Hat build of Keycloak 26.4 | rhbk/keycloak-rhel9:26.4-19 | Fixed | RHSA-2026:30050 |
| Red Hat build of Keycloak 26.4.13 | rhbk/keycloak-rhel9 | Fixed | RHSA-2026:30049 |
| Red Hat build of Keycloak 26.6 | rhbk/keycloak-operator-bundle:26.6.3-3 | Fixed | RHSA-2026:25097 |
| Red Hat build of Keycloak 26.6 | rhbk/keycloak-rhel9-operator:26.6-6 | Fixed | RHSA-2026:25097 |
| Red Hat build of Keycloak 26.6 | rhbk/keycloak-rhel9:26.6-6 | Fixed | RHSA-2026:25097 |
| Red Hat build of Keycloak 26.6.3 | rhbk/keycloak-rhel9 | Fixed | RHSA-2026:25098 |
No package ranges for this CVE.
Remediation
Vendor solution
To mitigate this vulnerability, ensure that Keycloak's LDAP user-storage providers are configured to connect only to trusted and secure LDAP servers. Avoid configuring LDAP federation with unverified or potentially malicious LDAP endpoints. Additionally, always use TLS for LDAP connections to prevent Man-in-the-Middle attacks. If an upstream LDAP server is compromised, it should be isolated and secured immediately.
Red Hat statement
This vulnerability in Keycloak presents a denial-of-service risk when an LDAP user-storage provider is configured. A highly privileged attacker, such as a realm administrator or through a compromised LDAP connection, can send a malformed LDAP password-policy response. This triggers an OutOfMemoryError, causing the Keycloak JVM to terminate and resulting in a complete outage of the node.
Red Hat mitigation
To mitigate this vulnerability, ensure that Keycloak's LDAP user-storage providers are configured to connect only to trusted and secure LDAP servers. Avoid configuring LDAP federation with unverified or potentially malicious LDAP endpoints. Additionally, always use TLS for LDAP connections to prevent Man-in-the-Middle attacks. If an upstream LDAP server is compromised, it should be isolated and secured immediately.
References (13)
- https://access.redhat.com/errata/RHSA-2026:25097 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:25098 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:30049 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:30050 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2026-9801 vdb-entryx_refsource_REDHATMitigationVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2482473 issue-trackingx_refsource_REDHATIssue TrackingVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-32718 Advisory
- https://github.com/advisories/GHSA-f6r7-6w34-x2gp Advisory
- https://github.com/keycloak/keycloak/commit/2c4fe42235ba8c265b1da3a30541a270d5bd8c39
- https://github.com/keycloak/keycloak/issues/49434
- https://github.com/keycloak/keycloak/pull/49514
- https://nvd.nist.gov/vuln/detail/CVE-2026-9801
- https://www.cve.org/CVERecord?id=CVE-2026-9801
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2026:25097 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/errata/RHSA-2026:25098 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/errata/RHSA-2026:30049 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/errata/RHSA-2026:30050 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/security/cve/CVE-2026-9801 | vdb-entryx_refsource_REDHATMitigationVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2482473 | issue-trackingx_refsource_REDHATIssue TrackingVendor Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-32718 | Advisory | |
| https://github.com/advisories/GHSA-f6r7-6w34-x2gp | Advisory | |
| https://github.com/keycloak/keycloak/commit/2c4fe42235ba8c265b1da3a30541a270d5bd8c39 | ||
| https://github.com/keycloak/keycloak/issues/49434 | ||
| https://github.com/keycloak/keycloak/pull/49514 | ||
| https://nvd.nist.gov/vuln/detail/CVE-2026-9801 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-9801 |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub