{"id":"CVE-2026-18212","title":"A flaw was found in the SAML Redirect Binding implementation of Keycloak, an open-source identity and access management solution","summary":"A flaw was found in the SAML Redirect Binding implementation of Keycloak, an open-source identity and access management solution. The issue occurs because the custom DEFLATE compression and decompression helpers fail to release native zl…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-401"],"vendor":"Red Hat","product":"keycloak-rhel9-container","affected":["keycloak-rhel9-container (all versions)","keycloak-rhel9-operator-container (all versions)","rhbk/keycloak-operator-bundle (all versions)","keycloak-services","rhbk-openshift-rhel9/rhbk-openshift-rhel9","keycloak-rhel9-container (all versions)","keycloak-rhel9-operator-bundle-container (all versions)","keycloak-rhel9-operator-container (all versions)","keycloak-services","rhbk-keycloak-rhel9/rhbk-keycloak-rhel9","rhbk-openshift-rhel9/rhbk-openshift-rhel9","keycloak-services (all versions)","keycloak-services","keycloak-services (all versions)"],"patched":["build_of_keycloak 26.4","build_of_keycloak 26.4.16","build_of_keycloak 26.6.7"],"published":"2026-09-16","updated":"2026-09-16","sourceUpdated":"2026-09-16T19:42:43.623","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-18212","references":[{"url":"https://access.redhat.com/errata/RHSA-2026:68276","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:68277","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:68278","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:68280","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/security/cve/CVE-2026-18212","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2508307","label":"secalert@redhat.com"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-18212.json"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-18212"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-18212"}],"tags":["nvd","cve.org","csaf","vex","red-hat"],"ssvc":{"exploitation":"none","automatable":"yes","technicalImpact":"partial","timestamp":"2026-09-16T18:25:11.882582Z"},"ingestedAt":"2026-09-16T14:57:28.029Z","epss":0.00523,"epssPercentile":0.43161,"slug":"CVE-2026-18212","body":"## Overview\n\nA flaw was found in the SAML Redirect Binding implementation of Keycloak, an open-source identity and access management solution. The issue occurs because the custom DEFLATE compression and decompression helpers fail to release native zlib memory after use. An unauthenticated attacker can exploit this by sending repeated malformed SAML requests, leading to native memory exhaustion and a denial of service.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Vendor advisories\n\n- **RHSA-2026:68276** · Red Hat · fixed in: Red Hat build of Keycloak 26.4 · released 2026-09-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:68276)\n- **RHSA-2026:68280** · Red Hat · fixed in: Red Hat build of Keycloak 26.4.16 · released 2026-09-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:68280)\n- **RHSA-2026:68278** · Red Hat · fixed in: Red Hat build of Keycloak 26.6.7 · released 2026-09-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:68278)\n- **Red Hat VEX** · Important · affected: Red Hat Data Grid 8, Red Hat Single Sign-On 7 · no fix planned: Red Hat Data Grid 8, Red Hat Single Sign-On 7 · updated 2026-09-16 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-18212.json)\n- **RHSA-2026:68277** · Red Hat · fixed in: Red Hat build of Keycloak 26.6 · released 2026-09-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:68277)","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}