VulnSea

rhbk/keycloak-operator-bundle vulnerabilities

CVEs whose affected-version data names the rhbk/keycloak-operator-bundle package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

17 CVEsRSS

CVE-2026-17526High· 7.2
5d ago

Keycloak is an open-source identity and access management solution

Keycloak is an open-source identity and access management solution. A vulnerability was discovered where a user with the impersonation role can impersonate a realm administrator. This allows the attacker to gain full administrative contr…

TwilightRed Hat · keycloak-rhel9-containerEPSS 0.45%via NVD
CVE-2026-19607Medium· 5.3
5d ago

A flaw was found in the first-broker-login flow of the keycloak-services component

A flaw was found in the first-broker-login flow of the keycloak-services component. This component handles the initial authentication and account linking when a user logs in via an external identity provider. The issue allows an attacker…

SunlitRed Hat · keycloak-rhel9-containerEPSS 0.51%via NVD
CVE-2026-18212High· 7.5
5d ago

A flaw was found in the SAML Redirect Binding implementation of Keycloak, an open-source identity and access management solution

A flaw was found in the SAML Redirect Binding implementation of Keycloak, an open-source identity and access management solution. The issue occurs because the custom DEFLATE compression and decompression helpers fail to release native zl…

TwilightRed Hat · keycloak-rhel9-containerEPSS 0.52%via NVD
CVE-2026-74909High· 8.1
5d ago

Keycloak provides a policy enforcer to protect applications by matching incoming web requests against defined security policies

Keycloak provides a policy enforcer to protect applications by matching incoming web requests against defined security policies. A flaw was found where the enforcer fails to correctly normalize web addresses that contain special encoded …

TwilightRed Hat · rhbk/keycloak-operator-bundleEPSS 0.89%via NVD
CVE-2026-79651High· 7.5
5d ago

A flaw was found in the theme localization endpoints of the keycloak-services component, which is the core service responsible for authentication flows and theme management in Keycloak

A flaw was found in the theme localization endpoints of the keycloak-services component, which is the core service responsible for authentication flows and theme management in Keycloak. The issue occurs because the system accepts arbitra…

TwilightRed Hat · keycloak-rhel9-containerEPSS 0.62%via NVD
CVE-2026-19729Medium· 4.9
1w ago

A flaw was found in the key provider component of the keycloak-services library, which is the core engine for the Red Hat Build of Keycloak

A flaw was found in the key provider component of the keycloak-services library, which is the core engine for the Red Hat Build of Keycloak. The issue occurs because a previous fix for path probing was incomplete, allowing a realm admini…

SunlitRed Hat · keycloak-rhel9-containerEPSS 0.56%via NVD
CVE-2026-18963Critical· 9.1PoC
1mo ago

A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak

A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. The issue allows an unauthenticated attacker to force the passwo…

AbyssalRed Hat · rhbk/keycloak-operator-bundleEPSS 3.2%via NVD
CVE-2025-3501High· 8.2
1y ago

A flaw was found in Keycloak

A flaw was found in Keycloak. By setting a verification policy to 'ALL', the trust store certificate verification is skipped, which is unintended.

TwilightRed Hat · keycloakEPSS 0.44%via NVD
CVE-2025-2559Medium· 4.9
1y ago

A flaw was found in Keycloak

A flaw was found in Keycloak. When the configuration uses JWT tokens for authentication, the tokens are cached until expiration. If a client uses JWT tokens with an excessively long expiration time, for example, 24 or 48 hours, the cache…

SunlitRed Hat · keycloakEPSS 0.68%via NVD
CVE-2025-1391Medium· 5.4
1y ago

A flaw was found in the Keycloak organization feature, which allows the incorrect assignment of an organization to a user if their username or email matches the organization’s domain pattern

A flaw was found in the Keycloak organization feature, which allows the incorrect assignment of an organization to a user if their username or email matches the organization’s domain pattern. This issue occurs at the mapper level, leadin…

SunlitRed Hat · keycloak-servicesEPSS 0.41%via NVD
CVE-2025-0604Medium· 5.4
1y ago

A flaw was found in Keycloak

A flaw was found in Keycloak. When an Active Directory user resets their password, the system updates it without performing an LDAP bind to validate the new credentials against AD. This vulnerability allows users whose AD accounts are ex…

SunlitRed Hat · keycloak-ldap-federationEPSS 0.59%via NVD
CVE-2024-9666Medium· 4.7
1y ago

A vulnerability was found in the Keycloak Server

A vulnerability was found in the Keycloak Server. The Keycloak Server is vulnerable to a denial of service (DoS) attack due to improper handling of proxy headers. When Keycloak is configured to accept incoming proxy headers, it may accep…

SunlitRed Hat · keycloakEPSS 0.40%via NVD
CVE-2024-10492Low· 2.7
1y ago

A vulnerability was found in Keycloak

A vulnerability was found in Keycloak. A user with high privileges could read sensitive information from a Vault file that is not within the expected context. This attacker must have previous high access to the Keycloak server in order t…

SunlitRed Hat · keycloakEPSS 0.71%via NVD
CVE-2024-10451Medium· 5.9
1y ago

A flaw was found in Keycloak

A flaw was found in Keycloak. This issue occurs because sensitive runtime values, such as passwords, may be captured during the Keycloak build process and embedded as default values in bytecode, leading to unintended information disclosu…

SunlitRed Hat · rhbk/keycloak-operator-bundleEPSS 0.92%via NVD
CVE-2024-10270Medium· 6.5
1y ago

A vulnerability was found in the Keycloak-services package

A vulnerability was found in the Keycloak-services package. If untrusted data is passed to the SearchQueryUtils method, it could lead to a denial of service (DoS) scenario by exhausting system resources due to a Regex complexity.

SunlitRed Hat · keycloakEPSS 1.3%via NVD
CVE-2023-6717Medium· 6.0
2y ago

A flaw was found in the SAML client registration in Keycloak that could allow an administrator to register malicious JavaScript URIs as Assertion Consumer Service POST Binding URLs (ACS), posing a Cross-Site Scripting (XSS) risk

A flaw was found in the SAML client registration in Keycloak that could allow an administrator to register malicious JavaScript URIs as Assertion Consumer Service POST Binding URLs (ACS), posing a Cross-Site Scripting (XSS) risk. This is…

SunlitRed Hat · keycloakEPSS 0.71%via NVD
CVE-2024-1249High· 7.4
2y ago

A flaw was found in Keycloak's OIDC component in the "checkLoginIframe," which allows unvalidated cross-origin messages

A flaw was found in Keycloak's OIDC component in the "checkLoginIframe," which allows unvalidated cross-origin messages. This flaw allows attackers to coordinate and send millions of requests in seconds using simple code, significantly i…

TwilightRed Hat · keycloakEPSS 0.45%via NVD
rhbk/keycloak-operator-bundle vulnerabilities (CVEs) · VulnSea