---
id: CVE-2026-2575
title: A flaw was found in Keycloak
summary: >-
  A flaw was found in Keycloak. An unauthenticated remote attacker can trigger
  an application level Denial of Service (DoS) by sending a highly compressed
  SAMLRequest through the SAML Redirect Binding. The server fails to enforce
  size limi…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'
cwe:
  - CWE-409
vendor: redhat
product: build_of_keycloak
affected:
  - 'build_of_keycloak >= 26.4, < 26.4.10'
patched:
  - build_of_keycloak 26.4.10
published: '2026-03-18'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T15:17:25.650'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-2575'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2026:3947'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:3948'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2026-2575'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2440149'
    label: secalert@redhat.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-03-18T13:34:34.411686Z'
epss: 0.00663
epssPercentile: 0.49712
ingestedAt: '2026-09-29T16:39:33.224Z'
---

## Overview

A flaw was found in Keycloak. An unauthenticated remote attacker can trigger an application level Denial of Service (DoS) by sending a highly compressed SAMLRequest through the SAML Redirect Binding. The server fails to enforce size limits during DEFLATE decompression, leading to an OutOfMemoryError (OOM) and subsequent process termination. This vulnerability allows an attacker to disrupt the availability of the service.

## Affected

- `build_of_keycloak >= 26.4, < 26.4.10`

## Remediation

Upgrade past the affected range:

- `build_of_keycloak 26.4.10`
