Keycloak
Keycloak · 16 CVEs
Keycloak-services: keycloak: replay protection bypass leads to unauthorized access via database driver semantics mismat…
Sep 17, 2026
Org.keycloak/keycloak-quarkus-server: keycloak: unauthorized access via jwt authorization grant with disabled users
Jul 16, 2026
Org.keycloak/keycloak-services: webauthn attestation statement verification bypass
Feb 27, 2026
Org.keycloak.storage.ldap: keycloak: deserialization of untrusted data in ldap user federation
Nov 25, 2025
Keycloak-server: debug default bind address
Nov 13, 2025
Org.keycloak.protocol.oidc.endpoints.logoutendpoint: offline session takeover due to reused authentication session id
Oct 28, 2025
Org.keycloak/keycloak-quarkus-server: unable to restrict access to the admin console
Oct 28, 2025
Keycloak: org.keycloak:keycloak-services: user can refresh offline session even after client's offline_access scope was…
Oct 23, 2025
Keycloak-server: too long and not settings compliant session
Oct 23, 2025
Keycloak: keycloak error_description injection on error pages
Sep 5, 2025
Org.keycloak/keycloak-model-storage-service: variable injection into environment variables
Aug 21, 2025
Org.keycloak/keycloak-services: keycloak smtp inject vulnerability
Aug 6, 2025
keycloak: remove other users MFA devices
May 4, 2020
keycloak: adapter endpoints are exposed via arbitrary URLs
Jan 8, 2020
keycloak: reset password token disclosure
Feb 21, 2018
JBoss KeyCloak before 1.0.3.Final allows remote attackers to cause a denial of service (resource consumption) via a lar…
Dec 29, 2017
keycloak: CSRF token fixation
Oct 26, 2017
keycloak: reflected XSS using HOST header
Oct 26, 2017
The org.keycloak.services.resources.SocialResource.callback method in JBoss KeyCloak before 1.0.3.Final allows remote a…
Oct 18, 2017
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-90997 | Keycloak-services: keycloak: replay protection bypass leads to unauthorized access via database driver semantics mismatch | HIGH | 0.40% | Sep 17, 2026 |
| CVE-2026-1609 | Org.keycloak/keycloak-quarkus-server: keycloak: unauthorized access via jwt authorization grant with disabled users | HIGH | 0.56% | Jul 16, 2026 |
| CVE-2025-12150 | Org.keycloak/keycloak-services: webauthn attestation statement verification bypass | LOW | 0.21% | Feb 27, 2026 |
| CVE-2025-13467 | Org.keycloak.storage.ldap: keycloak: deserialization of untrusted data in ldap user federation | MEDIUM | 0.44% | Nov 25, 2025 |
| CVE-2025-11538 | Keycloak-server: debug default bind address | MEDIUM | 0.40% | Nov 13, 2025 |
| CVE-2025-12390 | Org.keycloak.protocol.oidc.endpoints.logoutendpoint: offline session takeover due to reused authentication session id | MEDIUM | 0.14% | Oct 28, 2025 |
| CVE-2025-10939 | Org.keycloak/keycloak-quarkus-server: unable to restrict access to the admin console | LOW | 0.41% | Oct 28, 2025 |
| CVE-2025-12110 | Keycloak: org.keycloak:keycloak-services: user can refresh offline session even after client's offline_access scope was removed | MEDIUM | 0.30% | Oct 23, 2025 |
| CVE-2025-11429 | Keycloak-server: too long and not settings compliant session | MEDIUM | 0.24% | Oct 23, 2025 |
| CVE-2025-10044 | Keycloak: keycloak error_description injection on error pages | MEDIUM | 0.31% | Sep 5, 2025 |
| CVE-2025-9162 | Org.keycloak/keycloak-model-storage-service: variable injection into environment variables | MEDIUM | 0.50% | Aug 21, 2025 |
| CVE-2025-8419 | Org.keycloak/keycloak-services: keycloak smtp inject vulnerability | MEDIUM | 0.43% | Aug 6, 2025 |
| CVE-2020-10686 | keycloak: remove other users MFA devices | MEDIUM | 0.65% | May 4, 2020 |
| CVE-2019-14820 | keycloak: adapter endpoints are exposed via arbitrary URLs | MEDIUM | 0.72% | Jan 8, 2020 |
| CVE-2017-12161 | keycloak: reset password token disclosure | HIGH | 1.31% | Feb 21, 2018 |
| CVE-2014-3651 | JBoss KeyCloak before 1.0.3.Final allows remote attackers to cause a denial of service (resource consumption) via a large value in the size parameter to auth/q… | HIGH | 1.64% | Dec 29, 2017 |
| CVE-2017-12159 | keycloak: CSRF token fixation | HIGH | 2.71% | Oct 26, 2017 |
| CVE-2017-12158 | keycloak: reflected XSS using HOST header | MEDIUM | 1.02% | Oct 26, 2017 |
| CVE-2014-3709 | The org.keycloak.services.resources.SocialResource.callback method in JBoss KeyCloak before 1.0.3.Final allows remote attackers to conduct cross-site request f… | HIGH | 0.82% | Oct 18, 2017 |
Showing 1 to 16 of 16 CVEs