CVE-2023-6134Medium· 4.6▾ SunlitA flaw was found in Keycloak that prevents certain schemes in redirects, but permits them if a wildcard is appended to the token. This issue could allow an attacker to submit a specially crafted request leading to cross-site scripting (X…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 25.3 · likelihood 0.3 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 22.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.9%
0.9% → 1.3%
A flaw was found in Keycloak that prevents certain schemes in redirects, but permits them if a wildcard is appended to the token. This issue could allow an attacker to submit a specially crafted request leading to cross-site scripting (XSS) or further attacks. This flaw is the result of an incomplete fix for CVE-2020-10748.
single_sign-on < 7.6keycloak < 22.0.7openshift_container_platform = 4.11openshift_container_platform = 4.12openshift_container_platform_for_power = 4.9openshift_container_platform_for_power = 4.10openshift_container_platform_ibm_z_systems = 4.9openshift_container_platform_ibm_z_systems = 4.10single_sign-onUpgrade past the affected range:
single_sign-on 7.6keycloak 22.0.7Connected by shared product, vendor, weakness, or advisory.
CVE-2026-17059Medium· 6.5A flaw was found in the role-users endpoint of the keycloak-services library, which is the core component of the Keycloak identity and access management solution
CVE-2026-9796Medium· 6.5A flaw was found in Keycloak
CVE-2026-15154Medium· 6.5A flaw was found in `guardrails-detectors`, a component of Red Hat OpenShift AI
CVE-2026-16108Medium· 4.3A flaw was found in the default-groups REST endpoint and realm representation of Keycloak
CVE-2026-16106Medium· 4.9A flaw was found in the admin REST API of Keycloak, a solution for identity and access management
CVE-2026-16104Medium· 4.3A flaw was found in the authentication configuration endpoint of the keycloak-services component, which is the core engine for Red Hat Build of Keycloak identity and access management