Red Hat / Build of Keycloak
111 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-18967 | Keycloak-services: keycloak-services: saml onetimeuse assertion replay in idp-initiated broker flow | HIGH | 8.1 | Aug 6, 2026 |
| CVE-2026-15572 | Keycloak-services: keycloak-services: dcr protocol mapper type-swap policy bypass allows privilege escalation | HIGH | 8.8 | Aug 5, 2026 |
| CVE-2026-16442 | Keycloak-services: keycloak-services: saml idp-initiated broker login bypasses link-only restriction | CRITICAL | 9.8 | Aug 5, 2026 |
| CVE-2026-16100 | Keycloak-services: keycloak-services: unbounded metric cardinality in user event metrics via request-controlled error text | MEDIUM | 6.5 | Aug 5, 2026 |
| CVE-2026-16071 | Keycloak-services: keycloak-services: ldap entry-dn user search bypasses configured users dn boundary | MEDIUM | 5.4 | Aug 5, 2026 |
| CVE-2026-16102 | Keycloak-services: keycloak-services: default dcr policy allows role forgery via user property mappers | HIGH | 8.1 | Aug 5, 2026 |
| CVE-2026-15573 | Keycloak-services: keycloak-services: authorization bypass via unnormalized uri matching in pathmatcher | HIGH | 8.1 | Aug 5, 2026 |
| CVE-2026-16443 | Keycloak-services: keycloak-services: saml broker metadata import disables response signature validation | CRITICAL | 9.1 | Aug 5, 2026 |
| CVE-2026-18569 | Keycloak-services: keycloak-services: oidc backchannel logout accepts unsigned forged logout tokens | LOW | 3.7 | Aug 4, 2026 |
| CVE-2026-18573 | Keycloak-services: keycloak-services: client access-type policy condition bypass during client update | MEDIUM | 6.5 | Aug 2, 2026 |
| CVE-2026-18572 | Keycloak-services: keycloak-services: uma claim token can override authorization time-policy evaluation attributes | MEDIUM | 6.5 | Aug 2, 2026 |
| CVE-2026-18571 | Keycloak-services: keycloak-services: fgap v2 group assignment bypass during user creation | HIGH | 7.2 | Aug 2, 2026 |
| CVE-2026-18570 | Keycloak-services: keycloak-services: full-scope-disabled client policy validation bypass via omitted fullscopeallowed | MEDIUM | 5.4 | Aug 2, 2026 |
| CVE-2026-18209 | Keycloak-services: keycloak-services: oidc redirect_uri fragment bypass in http parameter pollution check | MEDIUM | 4.7 | Jul 31, 2026 |
| CVE-2026-18206 | Keycloak-services: keycloak-services: client policy source-host wildcard domain matching bypass | LOW | 3.7 | Jul 31, 2026 |
| CVE-2026-18214 | Keycloak-services: keycloak-services: google external access-token exchange bypasses hosted-domain restriction | HIGH | 8.1 | Jul 31, 2026 |
| CVE-2026-18203 | Keycloak-services: keycloak-services: group policy extendchildren matches sibling group path prefixes | MEDIUM | 6.5 | Jul 31, 2026 |
| CVE-2026-18211 | Keycloak-services: keycloak-services: secure-client-uris policy bypass via localhost-prefixed domains | MEDIUM | 5.4 | Jul 31, 2026 |
| CVE-2026-18208 | Keycloak-services: keycloak-services: inactive out-of-audience token introspection leaks signed jwt claim | MEDIUM | 6.5 | Jul 31, 2026 |
| CVE-2026-16105 | Keycloak-services: keycloak-services: missing per-role authorization on rolecontainerresource composite endpoints | MEDIUM | 4.9 | Jul 31, 2026 |
| CVE-2026-18215 | Keycloak-services: keycloak-services: microsoft external access-token exchange bypasses configured tenant | HIGH | 8.1 | Jul 31, 2026 |
| CVE-2026-18217 | Keycloak-services: keycloak-services: saml http-redirect binding response preserves query string leading to parameter pollution | MEDIUM | 4.7 | Jul 31, 2026 |
| CVE-2026-18218 | Keycloak-services: keycloak-services: client not-before revocation ignored when realm not-before is older but nonzero | MEDIUM | 5.4 | Jul 31, 2026 |
| CVE-2026-18201 | Keycloak-services: keycloak-services: generic identity-provider creation can bind brokers to organizations without manage-organizations | MEDIUM | 5.5 | Jul 29, 2026 |
| CVE-2026-18207 | Keycloak-services: keycloak-services: client policy source-group condition bypass via duplicate group name matching | MEDIUM | 6.5 | Jul 29, 2026 |
Showing 1 to 25 of 111 CVEs