{"id":"CVE-2026-105301","title":"A flaw was found in the X.509 client-certificate authenticator of Keycloak, a solution for identity and access management","summary":"A flaw was found in the X.509 client-certificate authenticator of Keycloak, a solution for identity and access management. The issue occurs when the server is configured to check certificate revocation using CRL Distribution Points or OC…","severity":"medium","cvss":4,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N","cwe":["CWE-918"],"vendor":"Red Hat","product":"keycloak-services","affected":["keycloak-services (all versions)","rhbk/keycloak-rhel9 (all versions)","keycloak-services"],"published":"2026-10-05","updated":"2026-10-05","sourceUpdated":"2026-10-05T06:16:58.207","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-105301","references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-105301","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2545797","label":"secalert@redhat.com"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-105301.json"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-105301"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105301"}],"tags":["nvd","cve.org","csaf","vex","red-hat"],"ingestedAt":"2026-10-05T06:13:49.198Z","slug":"CVE-2026-105301","body":"## Overview\n\nA flaw was found in the X.509 client-certificate authenticator of Keycloak, a solution for identity and access management. The issue occurs when the server is configured to check certificate revocation using CRL Distribution Points or OCSP. An attacker can provide a specially crafted certificate that points to a malicious server, causing Keycloak to make unauthorized outbound requests to internal or external endpoints before the certificate is fully validated. This can lead to a blind server-side request forgery (SSRF) attack.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Moderate · affected: Red Hat Build of Keycloak · no fix planned: Red Hat Build of Keycloak · updated 2026-10-05 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-105301.json)","depth":"sunlit","depthScore":22,"depthScoreParts":{"impact":22,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}