VulnSea

build_of_keycloak vulnerabilities

CVEs whose affected-version data names the build_of_keycloak package (maven, npm). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

72 CVEsRSS

CVE-2026-16103Medium· 4.3
2mo ago

A flaw was found in the keycloak-services component of Keycloak

A flaw was found in the keycloak-services component of Keycloak. This issue is an incomplete fix for CVE-2026-9798, where brute-force protection checks were added to the Client-Initiated Backchannel Authentication (CIBA) initiation handl…

Sunlitredhat · build_of_keycloakEPSS 0.34%via NVD
CVE-2026-16108Medium· 4.3
2mo ago

A flaw was found in the default-groups REST endpoint and realm representation of Keycloak

A flaw was found in the default-groups REST endpoint and realm representation of Keycloak. This component is responsible for managing groups that are automatically assigned to new users within a realm. The issue allows a delegated admini…

Sunlitredhat · build_of_keycloakEPSS 0.21%via NVD
CVE-2026-16106Medium· 4.9
2mo ago

A flaw was found in the admin REST API of Keycloak, a solution for identity and access management

A flaw was found in the admin REST API of Keycloak, a solution for identity and access management. The issue occurs when a delegated administrator attempts to remove a child role from a composite role. Due to missing authorization checks…

Sunlitredhat · build_of_keycloakEPSS 0.42%via NVD
CVE-2026-16104Medium· 4.3
2mo ago

A flaw was found in the authentication configuration endpoint of the keycloak-services component, which is the core engine for Red Hat Build of Keycloak identity and access management

A flaw was found in the authentication configuration endpoint of the keycloak-services component, which is the core engine for Red Hat Build of Keycloak identity and access management. The issue occurs because the system fails to mask se…

Sunlitredhat · build_of_keycloakEPSS 0.26%via NVD
CVE-2026-16093Medium· 5.4
2mo ago

Keycloak provides a mechanism called Client Policies to enforce security requirements on clients, such as requiring them to use signed JWTs for authentication

Keycloak provides a mechanism called Client Policies to enforce security requirements on clients, such as requiring them to use signed JWTs for authentication. A flaw was discovered where this enforcement can be bypassed. An attacker wit…

Sunlitredhat · build_of_keycloakEPSS 0.39%via NVD
CVE-2026-16089Medium· 5.4
2mo ago

A flaw was found in the keycloak-services component of Red Hat Build of Keycloak

A flaw was found in the keycloak-services component of Red Hat Build of Keycloak. The issue occurs because OAuth 2.0 authorization codes are not properly bound to the client that originally requested them. An attacker who can intercept a…

Sunlitredhat · build_of_keycloakEPSS 0.18%via NVD
CVE-2026-16072Medium· 4.9
2mo ago

A flaw was found in the organization management component of Keycloak

A flaw was found in the organization management component of Keycloak. A delegated administrator with permission to manage organizations can create an invitation for a non-existent email address and then retrieve the secret registration …

Sunlitredhat · build_of_keycloakEPSS 0.43%via NVD
CVE-2026-15943Medium· 5.5
2mo ago

A flaw was found in the Keycloak keycloak-services component, which handles the management of identity providers

A flaw was found in the Keycloak keycloak-services component, which handles the management of identity providers. The issue occurs when a delegated administrator updates an OIDC identity provider using a masked client secret sentinel val…

Sunlitredhat · build_of_keycloakEPSS 0.34%via NVD
CVE-2026-15945Medium· 4.3
2mo ago

A flaw was found in the group search functionality of the Keycloak server's administrative API

A flaw was found in the group search functionality of the Keycloak server's administrative API. When Fine-Grained Admin Permissions (FGAP) v2 is enabled, a delegated administrator can bypass access restrictions to view parent groups they…

Sunlitredhat · build_of_keycloakEPSS 0.31%via NVD
CVE-2026-1609High· 8.1
2mo ago

A flaw was found in Keycloak

A flaw was found in Keycloak. When the JSON Web Token (JWT) authorization grant preview feature is enabled and a user account is disabled, Keycloak fails to validate the user’s disabled status during JWT authorization grant processing. A…

Twilightredhat · build_of_keycloakEPSS 0.56%via NVD
CVE-2026-59889Medium· 6.5
2mo ago

com.fasterxml.jackson.core/jackson-databind: Jackson-databind: Privilege escalation via improper handling of @JsonUnwrapped properties (CVE…

A flaw was found in jackson-databind. The UnwrappedPropertyHandler.processUnwrapped() method, responsible for handling @JsonUnwrapped properties, replays buffered JSON without properly checking the active view. This allows an attacker to w…

SunlitRed Hat · Red Hat JBoss EAP 7.4 ELS for RHEL 8EPSS 0.35%via CSAF
CVE-2026-59899High· 7.5
2mo ago

io.netty/netty-codec-http: Netty: Memory exhaustion in netty-codec-http (decompression bomb) (CVE-2026-59899)

A flaw was found in the Netty netty-codec-http component. A remote attacker can send HTTP requests containing highly compressed data. The HTTP decoder in netty-codec-http fails to properly limit the decompression of this content, causing t…

TwilightRed Hat · Red Hat OpenShift Dev Spaces 3.30EPSS 0.34%via CSAF
CVE-2026-9800High· 8.1
2mo ago

A flaw was found in Keycloak Policy Enforcer

A flaw was found in Keycloak Policy Enforcer. This vulnerability allows any authenticated user to bypass all authorization policies, including role, scope, and User-Managed Access (UMA) permission checks. By including the configured acce…

Twilightredhat · build_of_keycloakEPSS 0.65%via NVD
CVE-2026-54518Medium· 6.5
3mo ago

jackson-databind: jackson-databind: Information disclosure and data manipulation via view-based access control bypass (CVE-2026-54518)

A flaw was found in jackson-databind. This vulnerability allows a remote attacker to bypass security view restrictions by sending specially crafted JSON (JavaScript Object Notation) data. The UnwrappedPropertyHandler component, which proce…

SunlitRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.35%via CSAF
CVE-2026-54512High· 8.1PoC
3mo ago

jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass (CVE-2026-54512)

A flaw was found in jackson-databind. This vulnerability allows a remote attacker to bypass the PolymorphicTypeValidator (PTV) when polymorphic typing is enabled and a type identifier contains generic parameters. By crafting a malicious ty…

MidnightRed Hat · Red Hat JBoss EAP 7.4 ELS for RHEL 8EPSS 0.87%via CSAF
CVE-2026-54513High· 8.1
3mo ago

jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution (CVE-2026-54513)

A flaw was found in jackson-databind, a library used for processing data. This vulnerability allows an attacker to bypass security controls designed to validate data types. By sending specially crafted input, an attacker can force the syst…

TwilightRed Hat · Red Hat Enterprise Linux AppStream E4S (v.8.8)EPSS 0.89%via CSAF
CVE-2026-54514Medium· 5.3
3mo ago

jackson-databind: jackson-databind: Information Disclosure via Eager DNS Resolution (CVE-2026-54514)

A flaw was found in jackson-databind, a library used for processing JSON data. This vulnerability allows a remote attacker to force the application to perform an attacker-chosen DNS (Domain Name System) query. This occurs when untrusted JS…

SunlitRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.37%via CSAF
CVE-2026-54515Medium· 5.3PoC
3mo ago

jackson-databind: jackson-databind: Ignored properties can be unexpectedly modified (CVE-2026-54515)

A flaw was found in jackson-databind. This vulnerability occurs in the data-binding functionality where properties intended to be ignored are incorrectly restored and become writable again. An attacker could potentially exploit this by pro…

TwilightRed Hat · Red Hat JBoss EAP 7.4 ELS for RHEL 8EPSS 0.37%via CSAF
CVE-2026-54516Medium· 5.3
3mo ago

jackson-databind: jackson-databind: Security bypass due to improper handling of renamed properties (CVE-2026-54516)

A flaw was found in jackson-databind. This vulnerability allows a remote attacker to bypass security controls by exploiting an issue in how properties are handled when both @JsonProperty (for renaming) and @JsonIgnore (for ignoring) annota…

SunlitRed Hat · Red Hat Satellite 6EPSS 0.45%via CSAF
CVE-2026-54517Medium· 5.3
3mo ago

jackson-databind: jackson-databind: Information disclosure via improper JsonView filter application (CVE-2026-54517)

A flaw was found in jackson-databind. A remote attacker can exploit this vulnerability due to an issue in how active-view (@JsonView) filters are applied. Specifically, setterless collections annotated with a restricted @JsonView can be po…

SunlitRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.38%via CSAF
CVE-2026-53550Medium· 5.3
3mo ago

js-yaml: js-yaml: Denial of Service via crafted YAML merge keys (CVE-2026-53550)

A flaw was found in js-yaml, a JavaScript YAML parser and dumper. A remote attacker can exploit this vulnerability by providing a specially crafted YAML document that repeatedly uses the same alias in a merge sequence. This can lead to alg…

SunlitRed Hat · Red Hat Openshift Data Foundation 4.18EPSS 0.39%via CSAF
CVE-2026-45536Medium· 4.0
3mo ago

netty-transport-native-epoll: netty-transport-native-kqueue: Netty: Denial of Service due to file descriptor leak in SCM_RIGHTS message han…

A flaw was found in Netty, a network application framework. A local attacker could exploit a vulnerability in the `netty_unix_socket_recvFd` function when handling `SCM_RIGHTS` messages in `Epoll` or `KQueue DomainSocketChannel` with `Doma…

SunlitRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.14%via CSAF
CVE-2026-45673Medium· 6.8
3mo ago

netty-resolver-dns: Netty DNS resolver: DNS Cache Poisoning via predictable transaction IDs (CVE-2026-45673)

A flaw was found in Netty's DNS resolver component. This vulnerability arises from the use of a predictable pseudo-random number generator (PRNG) for DNS transaction IDs and a static User Datagram Protocol (UDP) source port. This combinati…

SunlitRed Hat · OpenShift ServerlessEPSS 0.26%via CSAF
CVE-2026-47244Medium· 5.3
3mo ago

netty-codec-http2: Netty: Denial of Service via uncontrolled HTTP/2 concurrent streams (CVE-2026-47244)

A flaw was found in Netty, a network application framework. A remote attacker can exploit this vulnerability by sending a large number of HTTP/2 stream requests to a Netty HTTP/2 server. If the server does not explicitly limit concurrent s…

SunlitRed Hat · OpenShift ServerlessEPSS 0.29%via CSAF
CVE-2026-50020Medium· 5.3
3mo ago

netty-codec-http: Netty: Data manipulation via request-boundary confusion in HttpObjectDecoder (CVE-2026-50020)

A flaw was found in Netty. The HttpObjectDecoder component, which processes incoming HTTP requests, incorrectly skips certain control characters and whitespace before reading the first request line. This behavior, which goes beyond standar…

SunlitRed Hat · OpenShift ServerlessEPSS 0.23%via CSAF
CVE-2026-50560Medium· 5.3
3mo ago

netty-codec-http2: Netty: Denial of Service due to HTTP/2 max header size handling (CVE-2026-50560)

A flaw was found in Netty, a network application framework. A remote attacker can exploit a vulnerability in the HTTP/2 (Hypertext Transfer Protocol version 2) maximum header size handling. By sending a specific SETTINGS_MAX_HEADER_LIST_SI…

SunlitRed Hat · OpenShift ServerlessEPSS 0.30%via CSAF
CVE-2026-9796Medium· 6.5
3mo ago

A flaw was found in Keycloak

A flaw was found in Keycloak. An authenticated administrator with the `manage-clients` role can exploit a Time-of-check to time-of-use (TOCTOU) vulnerability in the name-based admin role checks. This allows the attacker to escalate their…

Sunlitredhat · build_of_keycloakEPSS 0.22%via NVD
CVE-2026-9798Medium· 4.3
3mo ago

A flaw was found in Keycloak, an open-source identity and access management solution

A flaw was found in Keycloak, an open-source identity and access management solution. When a user account is temporarily locked due to repeated failed login attempts, an attacker with valid client credentials can exploit the Client-Initi…

Sunlitredhat · build_of_keycloakEPSS 0.35%via NVD
CVE-2026-9793Medium· 5.9
3mo ago

A flaw was found in Keycloak

A flaw was found in Keycloak. When a JSON Web Encryption (JWE) encrypted request object is submitted, Keycloak may incorrectly process unsigned claims if the decrypted content is raw JSON, bypassing the configured signature policy. This …

Sunlitredhat · build_of_keycloakEPSS 0.16%via NVD
CVE-2026-9689Medium· 4.2
3mo ago

A flaw was found in Keycloak, an open-source identity and access management solution

A flaw was found in Keycloak, an open-source identity and access management solution. When a client application is configured to accept broad redirect Uniform Resource Identifiers (URIs), a remote attacker can manipulate the authenticati…

Sunlitredhat · build_of_keycloakEPSS 0.32%via NVD
build_of_keycloak vulnerabilities (CVEs) — page 2 · VulnSea