CVE-2026-105301Medium· 4.0▾ SunlitA flaw was found in the X.509 client-certificate authenticator of Keycloak, a solution for identity and access management. The issue occurs when the server is configured to check certificate revocation using CRL Distribution Points or OC…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 22 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
A flaw was found in the X.509 client-certificate authenticator of Keycloak, a solution for identity and access management. The issue occurs when the server is configured to check certificate revocation using CRL Distribution Points or OCSP. An attacker can provide a specially crafted certificate that points to a malicious server, causing Keycloak to make unauthorized outbound requests to internal or external endpoints before the certificate is fully validated. This can lead to a blind server-side request forgery (SSRF) attack.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-105306Medium· 6.5A flaw was found in the Dynamic Client Registration flow of the Keycloak identity and access management server
CVE-2026-105302Medium· 5.7A flaw was found in the User Session Note mapper of the Keycloak identity and access management solution
CVE-2026-103884Medium· 6.5A flaw was found in the X.509 client certificate authenticator of Keycloak
CVE-2026-51773High· 8.1An issue in the VMware datastore driver of OpenStack glance_store
CVE-2026-96448Medium· 6.6A flaw was found in the Fine-Grained Admin Permissions (FGAP v2) feature of Keycloak, an identity and access management solution
CVE-2026-97846Medium· 6.8Keycloak provides a feature called mTLS holder-of-key binding which ensures that a token can only be used by the client that originally requested it by binding it to their digital certificate