CVE-2024-8883Medium· 6.1▾ TwilightPoC availableA misconfiguration flaw was found in Keycloak. This issue can allow an attacker to redirect users to an arbitrary URL if a 'Valid Redirect URI' is set to http://localhost or http://127.0.0.1, enabling sensitive information such as author…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 33.6 · likelihood 0.4 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Aug 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
2.0%
Nuclei ×1
2.0% → 2.1%
A misconfiguration flaw was found in Keycloak. This issue can allow an attacker to redirect users to an arbitrary URL if a 'Valid Redirect URI' is set to http://localhost or http://127.0.0.1, enabling sensitive information such as authorization codes to be exposed to the attacker, potentially leading to session hijacking.
build_of_keycloakopenshift_container_platform = 4.11openshift_container_platform = 4.12openshift_container_platform_for_ibm_z = 4.9openshift_container_platform_for_ibm_z = 4.10openshift_container_platform_for_linuxone = 4.9openshift_container_platform_for_linuxone = 4.10openshift_container_platform_for_power = 4.9openshift_container_platform_for_power = 4.10single_sign-onsingle_sign-on = 7.6Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2023-6291High· 7.1A flaw was found in the redirect_uri validation logic in Keycloak
CVE-2023-6927Medium· 4.6A flaw was found in Keycloak
CVE-2025-3910Medium· 5.4A flaw was found in Keycloak
CVE-2026-17059Medium· 6.5A flaw was found in the role-users endpoint of the keycloak-services library, which is the core component of the Keycloak identity and access management solution
CVE-2026-9796Medium· 6.5A flaw was found in Keycloak
CVE-2026-16100Medium· 6.5A flaw was found in the user-event metrics recording of Keycloak