keycloak-services vulnerabilities
CVEs whose affected-version data names the keycloak-services package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
22 CVEsRSS
CVE-2026-94218Low· 3.1A flaw was found in the authentication session management of Keycloak, an identity and access management solution
A flaw was found in the authentication session management of Keycloak, an identity and access management solution. The issue occurs when an administrator enforces a stronger authentication flow, such as mandatory two-factor authenticatio…
CVE-2026-94217Low· 3.5A flaw was found in the User-Managed Access (UMA) implementation of Keycloak
A flaw was found in the User-Managed Access (UMA) implementation of Keycloak. The issue occurs in the authorization token endpoint when processing permission tickets. If two different users own resources with the same name, the system in…
CVE-2026-94213Medium· 4.9A flaw was found in the Authorization Services component of Keycloak, an open-source identity and access management solution
A flaw was found in the Authorization Services component of Keycloak, an open-source identity and access management solution. The issue occurs in the policy evaluation endpoint, which is used by administrators to test how access policies…
CVE-2026-94215Medium· 5.5A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution
A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution. The issue occurs because the API uses a per-request in-memory cache to resolve clients by their unique identifier without verifyi…
CVE-2026-94000Medium· 6.6A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution
A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution. The issue occurs in the group-membership endpoints where the system fails to check if a group grants administrative privileges be…
CVE-2026-93999Medium· 4.2A flaw was found in the OIDC protocol implementation of Keycloak, an open-source identity and access management solution
A flaw was found in the OIDC protocol implementation of Keycloak, an open-source identity and access management solution. The issue occurs during the token refresh process when the server restores requested audiences from stored client I…
CVE-2026-94001Medium· 6.5A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution
A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution. The endpoint used for deleting user credentials does not correctly check for fine-grained reset-password permissions. This allows…
CVE-2026-90997High· 7.4A flaw was found in Keycloak
A flaw was found in Keycloak. When deployed in stateless mode with MySQL or MariaDB, a mismatch in row-count semantics between the database driver and Keycloak's application logic allows an attacker to bypass replay protection. This vuln…
CVE-2026-17526High· 7.2Keycloak is an open-source identity and access management solution
Keycloak is an open-source identity and access management solution. A vulnerability was discovered where a user with the impersonation role can impersonate a realm administrator. This allows the attacker to gain full administrative contr…
CVE-2026-19607Medium· 5.3A flaw was found in the first-broker-login flow of the keycloak-services component
A flaw was found in the first-broker-login flow of the keycloak-services component. This component handles the initial authentication and account linking when a user logs in via an external identity provider. The issue allows an attacker…
CVE-2026-18212High· 7.5A flaw was found in the SAML Redirect Binding implementation of Keycloak, an open-source identity and access management solution
A flaw was found in the SAML Redirect Binding implementation of Keycloak, an open-source identity and access management solution. The issue occurs because the custom DEFLATE compression and decompression helpers fail to release native zl…
CVE-2026-74909High· 8.1Keycloak provides a policy enforcer to protect applications by matching incoming web requests against defined security policies
Keycloak provides a policy enforcer to protect applications by matching incoming web requests against defined security policies. A flaw was found where the enforcer fails to correctly normalize web addresses that contain special encoded …
CVE-2026-79651High· 7.5A flaw was found in the theme localization endpoints of the keycloak-services component, which is the core service responsible for authentication flows and theme management in Keycloak
A flaw was found in the theme localization endpoints of the keycloak-services component, which is the core service responsible for authentication flows and theme management in Keycloak. The issue occurs because the system accepts arbitra…
CVE-2026-92358Medium· 6.4A flaw was found in the first broker login flow of Keycloak
A flaw was found in the first broker login flow of Keycloak. When a user confirms an account-linking request from a different browser, a temporary proof is created to validate the link. However, this proof is not properly cleared after t…
CVE-2026-89298Medium· 4.9A flaw was found in the Dynamic Client Registration service of Keycloak, an open-source identity and access management solution
A flaw was found in the Dynamic Client Registration service of Keycloak, an open-source identity and access management solution. The issue occurs when a user with the view-clients role accesses the client registration endpoint to retriev…
CVE-2026-88770Medium· 6.5A flaw was found in the Device Authorization Grant flow of Keycloak, an identity and access management solution
A flaw was found in the Device Authorization Grant flow of Keycloak, an identity and access management solution. The issue occurs because the token redemption process fails to check if a user account is currently locked due to brute-forc…
CVE-2026-19729Medium· 4.9A flaw was found in the key provider component of the keycloak-services library, which is the core engine for the Red Hat Build of Keycloak
A flaw was found in the key provider component of the keycloak-services library, which is the core engine for the Red Hat Build of Keycloak. The issue occurs because a previous fix for path probing was incomplete, allowing a realm admini…
CVE-2026-79652Medium· 5.9A flaw was found in the JWT Bearer authorization grant implementation within the keycloak-services component of Red Hat Build of Keycloak
A flaw was found in the JWT Bearer authorization grant implementation within the keycloak-services component of Red Hat Build of Keycloak. This component handles various OAuth2 and OpenID Connect grant types used for issuing access token…
CVE-2026-18963Critical· 9.1PoCA flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak
A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. The issue allows an unauthenticated attacker to force the passwo…
CVE-2025-2559Medium· 4.9A flaw was found in Keycloak
A flaw was found in Keycloak. When the configuration uses JWT tokens for authentication, the tokens are cached until expiration. If a client uses JWT tokens with an excessively long expiration time, for example, 24 or 48 hours, the cache…
CVE-2025-1391Medium· 5.4A flaw was found in the Keycloak organization feature, which allows the incorrect assignment of an organization to a user if their username or email matches the organization’s domain pattern
A flaw was found in the Keycloak organization feature, which allows the incorrect assignment of an organization to a user if their username or email matches the organization’s domain pattern. This issue occurs at the mapper level, leadin…
CVE-2024-10270Medium· 6.5A vulnerability was found in the Keycloak-services package
A vulnerability was found in the Keycloak-services package. If untrusted data is passed to the SearchQueryUtils method, it could lead to a denial of service (DoS) scenario by exhausting system resources due to a Regex complexity.