VulnSea

build_of_keycloak vulnerabilities

CVEs whose affected-version data names the build_of_keycloak package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

73 CVEsRSS

CVE-2026-2603High· 8.1
6mo ago

A flaw was found in Keycloak

A flaw was found in Keycloak. A remote attacker could bypass security controls by sending a valid SAML response from an external Identity Provider (IdP) to the Keycloak SAML endpoint for IdP-initiated broker logins. This allows the attac…

▾ Twilightredhat · build_of_keycloakEPSS 0.72%via NVD
CVE-2026-2366Low· 3.1
6mo ago

A flaw was found in Keycloak

A flaw was found in Keycloak. An authorization bypass vulnerability in the Keycloak Admin API allows any authenticated user, even those without administrative privileges, to enumerate the organization memberships of other users. This inf…

▾ Sunlitredhat · build_of_keycloakEPSS 0.27%via NVD
CVE-2026-3429Medium· 4.2
6mo ago

A flaw was identified in the Account REST API of Keycloak that allows a user authenticated at a lower security level to perform sensitive actions intended only for higher-assurance sessions

A flaw was identified in the Account REST API of Keycloak that allows a user authenticated at a lower security level to perform sensitive actions intended only for higher-assurance sessions. Specifically, an attacker who has already obta…

▾ Sunlitredhat · build_of_keycloakEPSS 0.32%via NVD
CVE-2026-3009High· 8.1
6mo ago

A security flaw in the IdentityBrokerService.performLogin endpoint of Keycloak allows authentication to proceed using an Identity Provider (IdP) even after it has been disabled by an administrator

A security flaw in the IdentityBrokerService.performLogin endpoint of Keycloak allows authentication to proceed using an Identity Provider (IdP) even after it has been disabled by an administrator. An attacker who knows the IdP alias can…

▾ Twilightredhat · build_of_keycloakEPSS 0.47%via NVD
CVE-2025-12150Low· 3.1
7mo ago

A flaw was found in Keycloak’s WebAuthn registration component

A flaw was found in Keycloak’s WebAuthn registration component. This vulnerability allows an attacker to bypass the configured attestation policy and register untrusted or forged authenticators via submission of an attestation object wit…

▾ Sunlitredhat · build_of_keycloakEPSS 0.20%via NVD
CVE-2025-3910Medium· 5.4
1y ago

A flaw was found in Keycloak

A flaw was found in Keycloak. The org.keycloak.authorization package may be vulnerable to circumventing required actions, allowing users to circumvent requirements such as setting up two-factor authentication.

▾ Sunlitredhat · build_of_keycloakEPSS 0.44%via NVD
CVE-2025-0604Medium· 5.4
1y ago

A flaw was found in Keycloak

A flaw was found in Keycloak. When an Active Directory user resets their password, the system updates it without performing an LDAP bind to validate the new credentials against AD. This vulnerability allows users whose AD accounts are ex…

▾ SunlitRed Hat · keycloak-ldap-federationEPSS 0.59%via NVD
CVE-2024-12397High· 7.4
1y ago

A flaw was found in Quarkus-HTTP, which incorrectly parses cookies with certain value-delimiting characters in incoming requests

A flaw was found in Quarkus-HTTP, which incorrectly parses cookies with certain value-delimiting characters in incoming requests. This issue could allow an attacker to construct a cookie value to exfiltrate HttpOnly cookie values or spoo…

▾ TwilightRed Hat · Cryostat 4 on RHEL 9EPSS 0.82%via NVD
CVE-2024-10234Medium· 6.1⚠ Exploited0day
1y ago

A vulnerability was found in Wildfly, where a user may perform Cross-site scripting in the Wildfly deployment system

A vulnerability was found in Wildfly, where a user may perform Cross-site scripting in the Wildfly deployment system. This flaw allows an attacker or insider to execute a deployment with a malicious payload, which could trigger undesired…

▾ Midnightredhat · build_of_keycloakEPSS 0.64%via NVD
CVE-2024-8883Medium· 6.1PoC
2y ago

A misconfiguration flaw was found in Keycloak

A misconfiguration flaw was found in Keycloak. This issue can allow an attacker to redirect users to an arbitrary URL if a 'Valid Redirect URI' is set to http://localhost or http://127.0.0.1, enabling sensitive information such as author…

▾ Twilightredhat · build_of_keycloakEPSS 2.1%via NVD
CVE-2024-7341High· 7.1
2y ago

A session fixation issue was discovered in the SAML adapters provided by Keycloak

A session fixation issue was discovered in the SAML adapters provided by Keycloak. The session ID and JSESSIONID cookie are not changed at login time, even when the turnOffChangeSessionIdOnLogin option is configured. This flaw allows an …

▾ Twilightredhat · keycloakEPSS 0.85%via NVD
CVE-2024-7885High· 7.5
2y ago

A vulnerability was found in Undertow where the ProxyProtocolReadListener reuses the same StringBuilder instance across multiple requests

A vulnerability was found in Undertow where the ProxyProtocolReadListener reuses the same StringBuilder instance across multiple requests. This issue occurs when the parseProxyProtocolV1 method processes multiple requests on the same HTT…

▾ Twilightredhat · build_of_apache_camel_-_hawtioEPSS 2.6%via NVD
CVE-2024-1132High· 8.1
2y ago

A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect

A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. This issue could allow an attacker to construct a malicious request to bypass validation and access other URLs and sensitive information withi…

▾ Twilightredhat · build_of_keycloakEPSS 1.6%via NVD
build_of_keycloak vulnerabilities (CVEs) — page 3 · VulnSea