keycloak vulnerabilities
CVEs whose affected-version data names the keycloak package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
16 CVEsRSS
CVE-2025-12150Low· 3.1A flaw was found in Keycloak’s WebAuthn registration component
A flaw was found in Keycloak’s WebAuthn registration component. This vulnerability allows an attacker to bypass the configured attestation policy and register untrusted or forged authenticators via submission of an attestation object wit…
CVE-2025-8419Medium· 5.3A vulnerability was found in Keycloak-services
A vulnerability was found in Keycloak-services. Special characters used during e-mail registration may perform SMTP Injection and unexpectedly send short unwanted e-mails. The email is limited to 64 characters (limited local part of the …
CVE-2025-7365High· 7.1A flaw was found in Keycloak
A flaw was found in Keycloak. When an authenticated attacker attempts to merge accounts with another existing account during an identity provider (IdP) login, the attacker will subsequently be prompted to "review profile" information. Th…
CVE-2025-3501High· 8.2A flaw was found in Keycloak
A flaw was found in Keycloak. By setting a verification policy to 'ALL', the trust store certificate verification is skipped, which is unintended.
CVE-2025-2559Medium· 4.9A flaw was found in Keycloak
A flaw was found in Keycloak. When the configuration uses JWT tokens for authentication, the tokens are cached until expiration. If a client uses JWT tokens with an excessively long expiration time, for example, 24 or 48 hours, the cache…
CVE-2024-9666Medium· 4.7A vulnerability was found in the Keycloak Server
A vulnerability was found in the Keycloak Server. The Keycloak Server is vulnerable to a denial of service (DoS) attack due to improper handling of proxy headers. When Keycloak is configured to accept incoming proxy headers, it may accep…
CVE-2024-10492Low· 2.7A vulnerability was found in Keycloak
A vulnerability was found in Keycloak. A user with high privileges could read sensitive information from a Vault file that is not within the expected context. This attacker must have previous high access to the Keycloak server in order t…
CVE-2024-10270Medium· 6.5A vulnerability was found in the Keycloak-services package
A vulnerability was found in the Keycloak-services package. If untrusted data is passed to the SearchQueryUtils method, it could lead to a denial of service (DoS) scenario by exhausting system resources due to a Regex complexity.
CVE-2024-7341High· 7.1A session fixation issue was discovered in the SAML adapters provided by Keycloak
A session fixation issue was discovered in the SAML adapters provided by Keycloak. The session ID and JSESSIONID cookie are not changed at login time, even when the turnOffChangeSessionIdOnLogin option is configured. This flaw allows an …
CVE-2023-6717Medium· 6.0A flaw was found in the SAML client registration in Keycloak that could allow an administrator to register malicious JavaScript URIs as Assertion Consumer Service POST Binding URLs (ACS), posing a Cross-Site Scripting (XSS) risk
A flaw was found in the SAML client registration in Keycloak that could allow an administrator to register malicious JavaScript URIs as Assertion Consumer Service POST Binding URLs (ACS), posing a Cross-Site Scripting (XSS) risk. This is…
CVE-2024-1249High· 7.4A flaw was found in Keycloak's OIDC component in the "checkLoginIframe," which allows unvalidated cross-origin messages
A flaw was found in Keycloak's OIDC component in the "checkLoginIframe," which allows unvalidated cross-origin messages. This flaw allows attackers to coordinate and send millions of requests in seconds using simple code, significantly i…
CVE-2024-1132High· 8.1A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect
A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. This issue could allow an attacker to construct a malicious request to bypass validation and access other URLs and sensitive information withi…
CVE-2023-6291High· 7.1A flaw was found in the redirect_uri validation logic in Keycloak
A flaw was found in the redirect_uri validation logic in Keycloak. This issue may allow a bypass of otherwise explicitly allowed hosts. A successful attack may lead to an access token being stolen, making it possible for the attacker to …
CVE-2023-6927Medium· 4.6A flaw was found in Keycloak
A flaw was found in Keycloak. This issue may allow an attacker to steal authorization codes or tokens from clients using a wildcard in the JARM response mode "form_post.jwt" which could be used to bypass the security patch implemented to…
CVE-2023-6563High· 7.7An unconstrained memory consumption vulnerability was discovered in Keycloak
An unconstrained memory consumption vulnerability was discovered in Keycloak. It can be triggered in environments which have millions of offline tokens (> 500,000 users with each having at least 2 saved sessions). If an attacker creates …
CVE-2023-6134Medium· 4.6A flaw was found in Keycloak that prevents certain schemes in redirects, but permits them if a wildcard is appended to the token
A flaw was found in Keycloak that prevents certain schemes in redirects, but permits them if a wildcard is appended to the token. This issue could allow an attacker to submit a specially crafted request leading to cross-site scripting (X…