VulnSea

rhbk/keycloak-rhel9 vulnerabilities

CVEs whose affected-version data names the rhbk/keycloak-rhel9 package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

26 CVEsRSS

CVE-2026-94218Low· 3.1
today

A flaw was found in the authentication session management of Keycloak, an identity and access management solution

A flaw was found in the authentication session management of Keycloak, an identity and access management solution. The issue occurs when an administrator enforces a stronger authentication flow, such as mandatory two-factor authenticatio…

SunlitRed Hat · keycloak/rhbk-openshift-rhel9EPSS 0.20%via NVD
CVE-2026-94217Low· 3.5
today

A flaw was found in the User-Managed Access (UMA) implementation of Keycloak

A flaw was found in the User-Managed Access (UMA) implementation of Keycloak. The issue occurs in the authorization token endpoint when processing permission tickets. If two different users own resources with the same name, the system in…

SunlitRed Hat · keycloak/rhbk-openshift-rhel9EPSS 0.14%via NVD
CVE-2026-94213Medium· 4.9
today

A flaw was found in the Authorization Services component of Keycloak, an open-source identity and access management solution

A flaw was found in the Authorization Services component of Keycloak, an open-source identity and access management solution. The issue occurs in the policy evaluation endpoint, which is used by administrators to test how access policies…

SunlitRed Hat · keycloak/rhbk-openshift-rhel9EPSS 0.23%via NVD
CVE-2026-94215Medium· 5.5
today

A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution

A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution. The issue occurs because the API uses a per-request in-memory cache to resolve clients by their unique identifier without verifyi…

SunlitRed Hat · keycloak/rhbk-openshift-rhel9EPSS 0.18%via NVD
CVE-2026-94000Medium· 6.6
2d ago

A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution

A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution. The issue occurs in the group-membership endpoints where the system fails to check if a group grants administrative privileges be…

SunlitRed Hat · keycloak/rhbk-openshift-rhel9EPSS 0.24%via NVD
CVE-2026-93999Medium· 4.2
2d ago

A flaw was found in the OIDC protocol implementation of Keycloak, an open-source identity and access management solution

A flaw was found in the OIDC protocol implementation of Keycloak, an open-source identity and access management solution. The issue occurs during the token refresh process when the server restores requested audiences from stored client I…

SunlitRed Hat · keycloak/rhbk-openshift-rhel9EPSS 0.15%via NVD
CVE-2026-94001Medium· 6.5
2d ago

A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution

A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution. The endpoint used for deleting user credentials does not correctly check for fine-grained reset-password permissions. This allows…

SunlitRed Hat · keycloak/rhbk-openshift-rhel9EPSS 0.25%via NVD
CVE-2026-10832Medium· 5.9
3d ago

A flaw was found in the DERDecoder class within wildfly-elytron-asn1

A flaw was found in the DERDecoder class within wildfly-elytron-asn1. A remote attacker can exploit this resource exhaustion vulnerability by sending a specially crafted DER (Distinguished Encoding Rules) payload. The decoder attempts to…

SunlitRed Hat · wildfly-elytron-asn1EPSS 0.28%via NVD
CVE-2026-87743High· 7.5
3d ago

A flaw was found in Quarkus HTTP security

A flaw was found in Quarkus HTTP security. An unauthenticated attacker can exploit a discrepancy in how paths are normalized between the security matcher and HTTP request dispatchers. This allows the attacker to craft a URL that the secu…

TwilightRed Hat · exploit-intelligence/agent-client-rhel9EPSS 0.43%via NVD
CVE-2026-74909High· 8.1
5d ago

Keycloak provides a policy enforcer to protect applications by matching incoming web requests against defined security policies

Keycloak provides a policy enforcer to protect applications by matching incoming web requests against defined security policies. A flaw was found where the enforcer fails to correctly normalize web addresses that contain special encoded …

TwilightRed Hat · rhbk/keycloak-operator-bundleEPSS 0.89%via NVD
CVE-2026-79651High· 7.5
5d ago

A flaw was found in the theme localization endpoints of the keycloak-services component, which is the core service responsible for authentication flows and theme management in Keycloak

A flaw was found in the theme localization endpoints of the keycloak-services component, which is the core service responsible for authentication flows and theme management in Keycloak. The issue occurs because the system accepts arbitra…

TwilightRed Hat · keycloak-rhel9-containerEPSS 0.62%via NVD
CVE-2026-92358Medium· 6.4
5d ago

A flaw was found in the first broker login flow of Keycloak

A flaw was found in the first broker login flow of Keycloak. When a user confirms an account-linking request from a different browser, a temporary proof is created to validate the link. However, this proof is not properly cleared after t…

SunlitRed Hat · keycloak/rhbk-openshift-rhel9EPSS 0.28%via NVD
CVE-2026-89298Medium· 4.9
1w ago

A flaw was found in the Dynamic Client Registration service of Keycloak, an open-source identity and access management solution

A flaw was found in the Dynamic Client Registration service of Keycloak, an open-source identity and access management solution. The issue occurs when a user with the view-clients role accesses the client registration endpoint to retriev…

SunlitRed Hat · keycloak/rhbk-openshift-rhel9EPSS 0.24%via NVD
CVE-2026-88770Medium· 6.5
1w ago

A flaw was found in the Device Authorization Grant flow of Keycloak, an identity and access management solution

A flaw was found in the Device Authorization Grant flow of Keycloak, an identity and access management solution. The issue occurs because the token redemption process fails to check if a user account is currently locked due to brute-forc…

SunlitRed Hat · keycloak/rhbk-openshift-rhel9EPSS 0.21%via NVD
CVE-2026-79652Medium· 5.9
3w ago

A flaw was found in the JWT Bearer authorization grant implementation within the keycloak-services component of Red Hat Build of Keycloak

A flaw was found in the JWT Bearer authorization grant implementation within the keycloak-services component of Red Hat Build of Keycloak. This component handles various OAuth2 and OpenID Connect grant types used for issuing access token…

SunlitRed Hat · keycloak-rhel9-containerEPSS 0.21%via NVD
CVE-2026-18963Critical· 9.1PoC
1mo ago

A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak

A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. The issue allows an unauthenticated attacker to force the passwo…

AbyssalRed Hat · rhbk/keycloak-operator-bundleEPSS 3.2%via NVD
CVE-2025-3501High· 8.2
1y ago

A flaw was found in Keycloak

A flaw was found in Keycloak. By setting a verification policy to 'ALL', the trust store certificate verification is skipped, which is unintended.

TwilightRed Hat · keycloakEPSS 0.44%via NVD
CVE-2025-2559Medium· 4.9
1y ago

A flaw was found in Keycloak

A flaw was found in Keycloak. When the configuration uses JWT tokens for authentication, the tokens are cached until expiration. If a client uses JWT tokens with an excessively long expiration time, for example, 24 or 48 hours, the cache…

SunlitRed Hat · keycloakEPSS 0.68%via NVD
CVE-2025-1391Medium· 5.4
1y ago

A flaw was found in the Keycloak organization feature, which allows the incorrect assignment of an organization to a user if their username or email matches the organization’s domain pattern

A flaw was found in the Keycloak organization feature, which allows the incorrect assignment of an organization to a user if their username or email matches the organization’s domain pattern. This issue occurs at the mapper level, leadin…

SunlitRed Hat · keycloak-servicesEPSS 0.41%via NVD
CVE-2025-0604Medium· 5.4
1y ago

A flaw was found in Keycloak

A flaw was found in Keycloak. When an Active Directory user resets their password, the system updates it without performing an LDAP bind to validate the new credentials against AD. This vulnerability allows users whose AD accounts are ex…

SunlitRed Hat · keycloak-ldap-federationEPSS 0.59%via NVD
CVE-2024-9666Medium· 4.7
1y ago

A vulnerability was found in the Keycloak Server

A vulnerability was found in the Keycloak Server. The Keycloak Server is vulnerable to a denial of service (DoS) attack due to improper handling of proxy headers. When Keycloak is configured to accept incoming proxy headers, it may accep…

SunlitRed Hat · keycloakEPSS 0.40%via NVD
CVE-2024-10492Low· 2.7
1y ago

A vulnerability was found in Keycloak

A vulnerability was found in Keycloak. A user with high privileges could read sensitive information from a Vault file that is not within the expected context. This attacker must have previous high access to the Keycloak server in order t…

SunlitRed Hat · keycloakEPSS 0.71%via NVD
CVE-2024-10451Medium· 5.9
1y ago

A flaw was found in Keycloak

A flaw was found in Keycloak. This issue occurs because sensitive runtime values, such as passwords, may be captured during the Keycloak build process and embedded as default values in bytecode, leading to unintended information disclosu…

SunlitRed Hat · rhbk/keycloak-operator-bundleEPSS 0.92%via NVD
CVE-2024-10270Medium· 6.5
1y ago

A vulnerability was found in the Keycloak-services package

A vulnerability was found in the Keycloak-services package. If untrusted data is passed to the SearchQueryUtils method, it could lead to a denial of service (DoS) scenario by exhausting system resources due to a Regex complexity.

SunlitRed Hat · keycloakEPSS 1.3%via NVD
CVE-2023-6717Medium· 6.0
2y ago

A flaw was found in the SAML client registration in Keycloak that could allow an administrator to register malicious JavaScript URIs as Assertion Consumer Service POST Binding URLs (ACS), posing a Cross-Site Scripting (XSS) risk

A flaw was found in the SAML client registration in Keycloak that could allow an administrator to register malicious JavaScript URIs as Assertion Consumer Service POST Binding URLs (ACS), posing a Cross-Site Scripting (XSS) risk. This is…

SunlitRed Hat · keycloakEPSS 0.71%via NVD
CVE-2024-1249High· 7.4
2y ago

A flaw was found in Keycloak's OIDC component in the "checkLoginIframe," which allows unvalidated cross-origin messages

A flaw was found in Keycloak's OIDC component in the "checkLoginIframe," which allows unvalidated cross-origin messages. This flaw allows attackers to coordinate and send millions of requests in seconds using simple code, significantly i…

TwilightRed Hat · keycloakEPSS 0.45%via NVD
rhbk/keycloak-rhel9 vulnerabilities (CVEs) · VulnSea