Keycloak

Keycloak · 16 CVEs

CVE-2026-90997
HIGH

Keycloak-services: keycloak: replay protection bypass leads to unauthorized access via database driver semantics mismat…

Sep 17, 2026

CVE-2026-1609
HIGH

Org.keycloak/keycloak-quarkus-server: keycloak: unauthorized access via jwt authorization grant with disabled users

Jul 16, 2026

CVE-2025-12150
LOW

Org.keycloak/keycloak-services: webauthn attestation statement verification bypass

Feb 27, 2026

CVE-2025-13467
MEDIUM

Org.keycloak.storage.ldap: keycloak: deserialization of untrusted data in ldap user federation

Nov 25, 2025

CVE-2025-11538
MEDIUM

Keycloak-server: debug default bind address

Nov 13, 2025

CVE-2025-12390
MEDIUM

Org.keycloak.protocol.oidc.endpoints.logoutendpoint: offline session takeover due to reused authentication session id

Oct 28, 2025

CVE-2025-10939
LOW

Org.keycloak/keycloak-quarkus-server: unable to restrict access to the admin console

Oct 28, 2025

CVE-2025-12110
MEDIUM

Keycloak: org.keycloak:keycloak-services: user can refresh offline session even after client's offline_access scope was…

Oct 23, 2025

CVE-2025-11429
MEDIUM

Keycloak-server: too long and not settings compliant session

Oct 23, 2025

CVE-2025-10044
MEDIUM

Keycloak: keycloak error_description injection on error pages

Sep 5, 2025

CVE-2025-9162
MEDIUM

Org.keycloak/keycloak-model-storage-service: variable injection into environment variables

Aug 21, 2025

CVE-2025-8419
MEDIUM

Org.keycloak/keycloak-services: keycloak smtp inject vulnerability

Aug 6, 2025

CVE-2020-10686
MEDIUM

keycloak: remove other users MFA devices

May 4, 2020

CVE-2019-14820
MEDIUM

keycloak: adapter endpoints are exposed via arbitrary URLs

Jan 8, 2020

CVE-2017-12161
HIGH

keycloak: reset password token disclosure

Feb 21, 2018

CVE-2014-3651
HIGH

JBoss KeyCloak before 1.0.3.Final allows remote attackers to cause a denial of service (resource consumption) via a lar…

Dec 29, 2017

CVE-2017-12159
HIGH

keycloak: CSRF token fixation

Oct 26, 2017

CVE-2017-12158
MEDIUM

keycloak: reflected XSS using HOST header

Oct 26, 2017

CVE-2014-3709
HIGH

The org.keycloak.services.resources.SocialResource.callback method in JBoss KeyCloak before 1.0.3.Final allows remote a…

Oct 18, 2017

Showing 1 to 16 of 16 CVEs