---
id: CVE-2026-79651
title: >-
  A flaw was found in the theme localization endpoints of the keycloak-services
  component, which is the core service responsible for authentication flows and
  theme management in Keycloak
summary: >-
  A flaw was found in the theme localization endpoints of the keycloak-services
  component, which is the core service responsible for authentication flows and
  theme management in Keycloak. The issue occurs because the system accepts
  arbitra…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-400
vendor: Red Hat
product: keycloak-rhel9-container
affected:
  - keycloak-rhel9-container (all versions)
  - keycloak-rhel9-operator-container (all versions)
  - rhbk/keycloak-operator-bundle (all versions)
  - keycloak/rhbk-openshift-rhel9
  - keycloak-services
  - rhbk/keycloak-rhel9
  - keycloak-rhel9-container (all versions)
  - keycloak-rhel9-operator-bundle-container (all versions)
  - keycloak-rhel9-operator-container (all versions)
  - keycloak/rhbk-openshift-rhel9
  - keycloak-services
  - rhbk/keycloak-rhel9
  - keycloak-services
patched:
  - build_of_keycloak 26.4
  - build_of_keycloak 26.4.16
  - build_of_keycloak 26.6.7
published: '2026-09-16'
updated: '2026-09-16'
sourceUpdated: '2026-09-16T19:42:43.623'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-79651'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2026:68276'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:68277'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:68278'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:68280'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2026-79651'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2523345'
    label: secalert@redhat.com
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-79651.json
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-79651'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-79651'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-16T15:35:46.159784Z'
ingestedAt: '2026-09-16T14:57:28.027Z'
epss: 0.00806
epssPercentile: 0.54965
---

## Overview

A flaw was found in the theme localization endpoints of the keycloak-services component, which is the core service responsible for authentication flows and theme management in Keycloak. The issue occurs because the system accepts arbitrary locale tags from unauthenticated requests and stores them in a permanent in-memory cache without limits. An attacker can exploit this by sending a large number of unique locale tags, eventually causing the server to run out of memory and crash.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **RHSA-2026:68276** · Red Hat · fixed in: Red Hat build of Keycloak 26.4 · released 2026-09-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:68276)
- **RHSA-2026:68280** · Red Hat · fixed in: Red Hat build of Keycloak 26.4.16 · released 2026-09-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:68280)
- **RHSA-2026:68278** · Red Hat · fixed in: Red Hat build of Keycloak 26.6.7 · released 2026-09-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:68278)
- **RHSA-2026:68277** · Red Hat · fixed in: Red Hat build of Keycloak 26.6 · released 2026-09-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:68277)
