---
id: CVE-2026-1518
title: 'Rejected reason: DO NOT USE THIS CANDIDATE NUMBER'
summary: >-
  Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. After further review by the
  Keycloak project and Red Hat, the reported SSRF via client
  registration/backchannel notification URIs was determined not to constitute a
  security vulnerabilit…
severity: none
published: '2026-02-02'
updated: '2026-07-24'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-1518'
tags:
  - nvd
epss: 0.00236
epssPercentile: 0.14728
ingestedAt: '2026-07-24T15:30:58.096Z'
---

## Overview

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. After further review by the Keycloak project and Red Hat, the reported SSRF via client registration/backchannel notification URIs was determined not to constitute a security vulnerability. The reported behavior is expected administrator-controlled functionality, and Keycloak provides documented mitigations through Client Policies, including the Secure Client URIs Pattern executor. Therefore, this CVE has been rejected.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
