keycloak has 3 CVEs on record. 3 were published in the last 90 days. The median CVSS is 7.4 (high). Most affected products: org.keycloak:keycloak-services (2), keycloak-services (1).
CVEs per month
Last 12 months, by publish date
1025/101125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/09
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.4
- Publish → KEV
- —
- Last 90 days
- 3 prev 0
Weakness classes
Products
- org.keycloak:keycloak-services 2
- keycloak-services 1
3
Total CVEs
0
Critical
0
CISA KEV
0
Exploited
keycloak vulnerabilities
CVEs affecting keycloak, newest first. Open any entry for full detail, references, and exploit status.
3 CVEsRSS
CVE-2026-90997High· 7.4A flaw was found in Keycloak
A flaw was found in Keycloak. When deployed in stateless mode with MySQL or MariaDB, a mismatch in row-count semantics between the database driver and Keycloak's application logic allows an attacker to bypass replay protection. This vuln…
▾ TwilightKeycloak · keycloak-servicesEPSS 0.40%via NVD
CVE-2026-2092High· 7.7Keycloak: Unauthorized access via improper validation of encrypted SAML assertions
Keycloak: Unauthorized access via improper validation of encrypted SAML assertions
▾ Twilightkeycloak · org.keycloak:keycloak-servicesEPSS 0.31%via GHSA
CVE-2026-9795High· 7.3Keycloak has privilege escalation via improper scope mapping enforcement
Keycloak has privilege escalation via improper scope mapping enforcement
▾ Twilightkeycloak · org.keycloak:keycloak-servicesEPSS 0.35%via GHSA