VulnSea

keycloak-rhel9-operator-bundle-container vulnerabilities

CVEs whose affected-version data names the keycloak-rhel9-operator-bundle-container package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

7 CVEsRSS

CVE-2026-17526High· 7.2
5d ago

Keycloak is an open-source identity and access management solution

Keycloak is an open-source identity and access management solution. A vulnerability was discovered where a user with the impersonation role can impersonate a realm administrator. This allows the attacker to gain full administrative contr…

TwilightRed Hat · keycloak-rhel9-containerEPSS 0.45%via NVD
CVE-2026-19607Medium· 5.3
5d ago

A flaw was found in the first-broker-login flow of the keycloak-services component

A flaw was found in the first-broker-login flow of the keycloak-services component. This component handles the initial authentication and account linking when a user logs in via an external identity provider. The issue allows an attacker…

SunlitRed Hat · keycloak-rhel9-containerEPSS 0.51%via NVD
CVE-2026-18212High· 7.5
5d ago

A flaw was found in the SAML Redirect Binding implementation of Keycloak, an open-source identity and access management solution

A flaw was found in the SAML Redirect Binding implementation of Keycloak, an open-source identity and access management solution. The issue occurs because the custom DEFLATE compression and decompression helpers fail to release native zl…

TwilightRed Hat · keycloak-rhel9-containerEPSS 0.52%via NVD
CVE-2026-79651High· 7.5
5d ago

A flaw was found in the theme localization endpoints of the keycloak-services component, which is the core service responsible for authentication flows and theme management in Keycloak

A flaw was found in the theme localization endpoints of the keycloak-services component, which is the core service responsible for authentication flows and theme management in Keycloak. The issue occurs because the system accepts arbitra…

TwilightRed Hat · keycloak-rhel9-containerEPSS 0.62%via NVD
CVE-2026-19729Medium· 4.9
1w ago

A flaw was found in the key provider component of the keycloak-services library, which is the core engine for the Red Hat Build of Keycloak

A flaw was found in the key provider component of the keycloak-services library, which is the core engine for the Red Hat Build of Keycloak. The issue occurs because a previous fix for path probing was incomplete, allowing a realm admini…

SunlitRed Hat · keycloak-rhel9-containerEPSS 0.56%via NVD
CVE-2026-17615High· 7.5
3w ago

A flaw was found in RESTEasy's SourceProvider

A flaw was found in RESTEasy's SourceProvider. This vulnerability allows an unauthenticated attacker to perform an unauthenticated remote file read. By sending a specially crafted XML body with a DOCTYPE declaration referencing external …

TwilightRed Hat · keycloak-rhel9-containerEPSS 0.35%via NVD
CVE-2026-79652Medium· 5.9
3w ago

A flaw was found in the JWT Bearer authorization grant implementation within the keycloak-services component of Red Hat Build of Keycloak

A flaw was found in the JWT Bearer authorization grant implementation within the keycloak-services component of Red Hat Build of Keycloak. This component handles various OAuth2 and OpenID Connect grant types used for issuing access token…

SunlitRed Hat · keycloak-rhel9-containerEPSS 0.21%via NVD
keycloak-rhel9-operator-bundle-container vulnerabilities (CVEs) · VulnSea