keycloak/rhbk-openshift-rhel9 vulnerabilities
CVEs whose affected-version data names the keycloak/rhbk-openshift-rhel9 package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
15 CVEsRSS
CVE-2026-94218Low· 3.1A flaw was found in the authentication session management of Keycloak, an identity and access management solution
A flaw was found in the authentication session management of Keycloak, an identity and access management solution. The issue occurs when an administrator enforces a stronger authentication flow, such as mandatory two-factor authenticatio…
CVE-2026-94217Low· 3.5A flaw was found in the User-Managed Access (UMA) implementation of Keycloak
A flaw was found in the User-Managed Access (UMA) implementation of Keycloak. The issue occurs in the authorization token endpoint when processing permission tickets. If two different users own resources with the same name, the system in…
CVE-2026-94213Medium· 4.9A flaw was found in the Authorization Services component of Keycloak, an open-source identity and access management solution
A flaw was found in the Authorization Services component of Keycloak, an open-source identity and access management solution. The issue occurs in the policy evaluation endpoint, which is used by administrators to test how access policies…
CVE-2026-94215Medium· 5.5A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution
A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution. The issue occurs because the API uses a per-request in-memory cache to resolve clients by their unique identifier without verifyi…
CVE-2026-94000Medium· 6.6A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution
A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution. The issue occurs in the group-membership endpoints where the system fails to check if a group grants administrative privileges be…
CVE-2026-93999Medium· 4.2A flaw was found in the OIDC protocol implementation of Keycloak, an open-source identity and access management solution
A flaw was found in the OIDC protocol implementation of Keycloak, an open-source identity and access management solution. The issue occurs during the token refresh process when the server restores requested audiences from stored client I…
CVE-2026-94001Medium· 6.5A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution
A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution. The endpoint used for deleting user credentials does not correctly check for fine-grained reset-password permissions. This allows…
CVE-2026-87743High· 7.5A flaw was found in Quarkus HTTP security
A flaw was found in Quarkus HTTP security. An unauthenticated attacker can exploit a discrepancy in how paths are normalized between the security matcher and HTTP request dispatchers. This allows the attacker to craft a URL that the secu…
CVE-2026-74909High· 8.1Keycloak provides a policy enforcer to protect applications by matching incoming web requests against defined security policies
Keycloak provides a policy enforcer to protect applications by matching incoming web requests against defined security policies. A flaw was found where the enforcer fails to correctly normalize web addresses that contain special encoded …
CVE-2026-79651High· 7.5A flaw was found in the theme localization endpoints of the keycloak-services component, which is the core service responsible for authentication flows and theme management in Keycloak
A flaw was found in the theme localization endpoints of the keycloak-services component, which is the core service responsible for authentication flows and theme management in Keycloak. The issue occurs because the system accepts arbitra…
CVE-2026-92358Medium· 6.4A flaw was found in the first broker login flow of Keycloak
A flaw was found in the first broker login flow of Keycloak. When a user confirms an account-linking request from a different browser, a temporary proof is created to validate the link. However, this proof is not properly cleared after t…
CVE-2026-89298Medium· 4.9A flaw was found in the Dynamic Client Registration service of Keycloak, an open-source identity and access management solution
A flaw was found in the Dynamic Client Registration service of Keycloak, an open-source identity and access management solution. The issue occurs when a user with the view-clients role accesses the client registration endpoint to retriev…
CVE-2026-88770Medium· 6.5A flaw was found in the Device Authorization Grant flow of Keycloak, an identity and access management solution
A flaw was found in the Device Authorization Grant flow of Keycloak, an identity and access management solution. The issue occurs because the token redemption process fails to check if a user account is currently locked due to brute-forc…
CVE-2026-79652Medium· 5.9A flaw was found in the JWT Bearer authorization grant implementation within the keycloak-services component of Red Hat Build of Keycloak
A flaw was found in the JWT Bearer authorization grant implementation within the keycloak-services component of Red Hat Build of Keycloak. This component handles various OAuth2 and OpenID Connect grant types used for issuing access token…
CVE-2026-19611High· 7.4Wildfly-elytron: org.wildfly.security/wildfly-elytron-password-impl: wildfly-elytron: password keyspace reduction via nfkc fullwidth folding
A flaw was found in WildFly Elytron. Password hashing and verification normalize input with Unicode NFKC, which can collapse fullwidth characters to ASCII equivalents. A remote attacker can more easily guess affected passwords by using a…