CVE-2024-1132High· 8.1▾ TwilightA flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. This issue could allow an attacker to construct a malicious request to bypass validation and access other URLs and sensitive information withi…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 44.6 · likelihood 0.3 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
1.6%
A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. This issue could allow an attacker to construct a malicious request to bypass validation and access other URLs and sensitive information within the domain or conduct further attacks. This flaw affects any client that utilizes a wildcard in the Valid Redirect URIs field, and requires user interaction within the malicious URL.
build_of_keycloakjboss_middleware_text-only_advisories = 1.0keycloak >= 21.1.0, < 22.0.10keycloak >= 23.0.0, < 24.0.3migration_toolkit_for_applications = 1.0migration_toolkit_for_runtimesopenshift_container_platform = 4.11openshift_container_platform = 4.12openshift_container_platform_for_ibm_z = 4.9openshift_container_platform_for_ibm_z = 4.10openshift_container_platform_for_linuxone = 4.9openshift_container_platform_for_linuxone = 4.10openshift_container_platform_for_power = 4.9openshift_container_platform_for_power = 4.10single_sign-onsingle_sign-on = 7.6Upgrade past the affected range:
keycloak 24.0.3Connected by shared product, vendor, weakness, or advisory.
CVE-2025-3910Medium· 5.4A flaw was found in Keycloak
CVE-2026-17059Medium· 6.5A flaw was found in the role-users endpoint of the keycloak-services library, which is the core component of the Keycloak identity and access management solution
CVE-2026-9796Medium· 6.5A flaw was found in Keycloak
CVE-2026-71475Medium· 6.8A flaw was found in insights-client
CVE-2026-16100Medium· 6.5A flaw was found in the user-event metrics recording of Keycloak
CVE-2026-16071Medium· 5.4A flaw was found in the LDAP storage provider of Keycloak, which is used to federate user identities from external directories