Red Hat Build of Keycloak

54 known vulnerabilities in Red Hat Build of Keycloak, 1 critical, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-105306 CVSS 6.5 medium A flaw was found in the Dynamic Client Registration flow of the Keycloak identity and access management server. The issue occurs because…
  • CVE-2026-105302 CVSS 5.7 medium A flaw was found in the User Session Note mapper of the Keycloak identity and access management solution. The issue occurs because the…
  • CVE-2026-105301 CVSS 4.0 medium A flaw was found in the X.509 client-certificate authenticator of Keycloak, a solution for identity and access management. The issue…
  • CVE-2026-103884 CVSS 6.5 medium A flaw was found in the X.509 client certificate authenticator of Keycloak. When CRL Distribution Point checking is enabled, the server…
  • CVE-2026-101333 CVSS 3.7 low A flaw was found in the Micrometer user-event metrics listener of Keycloak, a solution for integrated identity and access management. The…
  • CVE-2026-96448 CVSS 6.6 medium A flaw was found in the Fine-Grained Admin Permissions (FGAP v2) feature of Keycloak, an identity and access management solution. The…
  • CVE-2026-97846 CVSS 6.8 medium Keycloak provides a feature called mTLS holder-of-key binding which ensures that a token can only be used by the client that originally…
  • CVE-2026-97311 CVSS 4.3 medium A flaw was found in the Admin REST API of Keycloak, an identity and access management solution. The endpoints used to retrieve groups…
  • CVE-2026-97177 CVSS 6.6 medium A flaw was found in the user update mechanism of the Keycloak Admin REST API. When Fine-Grained Admin Permissions are enabled, the system…
  • CVE-2026-97176 CVSS 4.2 medium A flaw was found in the Level of Authentication enforcement mechanism of Keycloak, an identity and access management solution. The issue…
  • CVE-2026-96446 CVSS 4.2 medium A flaw was found in the Pushed Authorization Request PAR implementation of Keycloak. The issue occurs when the silent authentication path…
  • CVE-2026-96445 CVSS 6.8 medium A flaw was found in the Conditional OTP authenticator of Keycloak, an identity and access management solution. The issue occurs when the…
  • CVE-2026-95503 CVSS 6.8 medium A flaw was found in the Kerberos federation provider of Keycloak, an open-source identity and access management solution. When Kerberos…
  • CVE-2026-94218 CVSS 3.1 low A flaw was found in the authentication session management of Keycloak, an identity and access management solution. The issue occurs when…
  • CVE-2026-94217 CVSS 3.5 low A flaw was found in the User-Managed Access (UMA) implementation of Keycloak. The issue occurs in the authorization token endpoint when…
  • CVE-2026-94215 CVSS 5.5 medium A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution. The issue occurs because the…
  • CVE-2026-94213 CVSS 4.9 medium A flaw was found in the Authorization Services component of Keycloak, an open-source identity and access management solution. The issue…
  • CVE-2026-94001 CVSS 6.5 medium A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution. The endpoint used for deleting…
  • CVE-2026-94000 CVSS 6.6 medium A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution. The issue occurs in the…
  • CVE-2026-93999 CVSS 4.2 medium A flaw was found in the OIDC protocol implementation of Keycloak, an open-source identity and access management solution. The issue occurs…
  • CVE-2026-93574 CVSS 6.5 medium A flaw was found in Netty's `netty-codec-http` component. A remote attacker could exploit this vulnerability by sending a specially…
  • CVE-2026-93562 CVSS 6.5 medium A flaw was found in Netty's HTTP/1 decoder. Incomplete validation of malformed Transfer-Encoding headers allows a remote attacker to…
  • CVE-2026-93432 CVSS 6.1 medium A flaw was found in the Quarkus Qute template engine. When the {#eval} section helper processes a sub-template, it fails to pass the…
  • CVE-2026-93579 CVSS 6.5 medium A flaw was found in Netty's HTTP/2 stack. This vulnerability allows a remote attacker to inject prohibited characters, such as NUL, Line…
  • CVE-2026-93573 CVSS 6.5 medium A flaw was found in Netty's HTTP/1.1 decoder. This vulnerability allows a remote attacker to bypass `Transfer-Encoding` header validation…
  • CVE-2026-93569 CVSS 8.2 high A flaw was found in Netty. A remote unauthenticated attacker can exploit a vulnerability in Netty's HTTP/1 to HTTP/2 conversion process…
  • CVE-2026-93568 CVSS 7.5 high A flaw was found in Netty. A remote attacker could exploit this vulnerability by sending specially crafted HTTP/2 or HTTP/3 Extended…
  • CVE-2026-93567 CVSS 7.5 high A flaw was found in Netty's HTTP/2 codec. When converting HTTP/1 CONNECT requests to HTTP/2, the component incorrectly uses the Host…
  • CVE-2026-93566 CVSS 6.5 medium A flaw was found in Netty. A remote attacker could exploit this by sending a specially crafted HTTP request that includes control…
  • CVE-2026-93565 CVSS 7.5 high A flaw was found in Netty RtspDecoder. The `RtspMethods.valueOf()` function incorrectly strips trailing control bytes from method tokens…