CVE-2026-2575Medium· 5.3▾ SunlitA flaw was found in Keycloak. An unauthenticated remote attacker can trigger an application level Denial of Service (DoS) by sending a highly compressed SAMLRequest through the SAML Redirect Binding. The server fails to enforce size limi…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.7%
A flaw was found in Keycloak. An unauthenticated remote attacker can trigger an application level Denial of Service (DoS) by sending a highly compressed SAMLRequest through the SAML Redirect Binding. The server fails to enforce size limits during DEFLATE decompression, leading to an OutOfMemoryError (OOM) and subsequent process termination. This vulnerability allows an attacker to disrupt the availability of the service.
build_of_keycloak >= 26.4, < 26.4.10Upgrade past the affected range:
build_of_keycloak 26.4.10Connected by shared product, vendor, weakness, or advisory.
CVE-2026-3009High· 8.1A security flaw in the IdentityBrokerService.performLogin endpoint of Keycloak allows authentication to proceed using an Identity Provider (IdP) even after it has been disabled by an administrator
CVE-2026-2092High· 7.7A flaw was found in Keycloak
CVE-2026-2603High· 8.1A flaw was found in Keycloak
CVE-2026-7307High· 7.5A flaw was found in Keycloak
CVE-2026-7507High· 7.5A session fixation vulnerability was found in Keycloak's login-actions endpoints
CVE-2026-4634High· 7.5A flaw was found in Keycloak