redhat / build_of_keycloak
64 known vulnerabilities in redhat build_of_keycloak.
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2024-7885 | Medium | 2.6% | 7.5 | A vulnerability was found in Undertow where the ProxyProtocolReadListener reuses… | |
| CVE-2024-1132 | Medium | 1.6% | 8.1 | A flaw was found in Keycloak, where it does not properly validate URLs included … | |
| CVE-2024-7341 | Medium | 0.8% | 7.1 | A session fixation issue was discovered in the SAML adapters provided by Keycloa… | |
| CVE-2026-7307 | Medium | 0.7% | 7.5 | A flaw was found in Keycloak. A remote, unauthenticated attacker can send a spec… | |
| CVE-2026-9800 | Medium | 0.7% | 8.1 | A flaw was found in Keycloak Policy Enforcer. This vulnerability allows any auth… | |
| CVE-2026-1609 | Medium | 0.6% | 8.1 | A flaw was found in Keycloak. When the JSON Web Token (JWT) authorization grant … | |
| CVE-2026-2603 | Medium | 0.4% | 8.1 | A flaw was found in Keycloak. A remote attacker could bypass security controls b… | |
| CVE-2026-15572 | Medium | 0.4% | 8.8 | A flaw was found in Keycloak's Dynamic Client Registration (DCR) security policy… | |
| CVE-2026-3009 | Medium | 0.3% | 8.1 | A security flaw in the IdentityBrokerService.performLogin endpoint of Keycloak a… | |
| CVE-2026-16102 | Medium | 0.3% | 8.1 | A flaw was found in the Dynamic Client Registration (DCR) component of Keycloak,… | |
| CVE-2026-15573 | Medium | 0.3% | 8.1 | A flaw was found in Keycloak's Authorization Services. The component responsible… | |
| CVE-2026-2092 | Medium | 0.3% | 7.7 | A flaw was found in Keycloak. Keycloak's Security Assertion Markup Language (SAM… | |
| CVE-2026-16442 | Medium | 0.2% | 7.4 | A flaw was found in the SAML broker component of Keycloak, which is used to mana… | |
| CVE-2026-16443 | Medium | 0.2% | 7.4 | A flaw was found in the SAML metadata import functionality of the keycloak-servi… | |
| CVE-2024-8883 | Low | 2.1% | 6.1 | A misconfiguration flaw was found in Keycloak. This issue can allow an attacker … | |
| CVE-2024-10234 | Low | 0.6% | 6.1 | A vulnerability was found in Wildfly, where a user may perform Cross-site script… | |
| CVE-2026-17059 | Low | 0.5% | 6.5 | A flaw was found in the role-users endpoint of the keycloak-services library, wh… | |
| CVE-2026-4629 | Low | 0.5% | 6.5 | A flaw was found in Keycloak. A highly privileged user with `manage-clients` per… | |
| CVE-2026-16072 | Low | 0.4% | 4.9 | A flaw was found in the organization management component of Keycloak. A delegat… | |
| CVE-2026-16106 | Low | 0.4% | 4.9 | A flaw was found in the admin REST API of Keycloak, a solution for identity and … | |
| CVE-2026-16100 | Low | 0.4% | 6.5 | A flaw was found in the user-event metrics recording of Keycloak. When metrics a… | |
| CVE-2026-16093 | Low | 0.4% | 5.4 | Keycloak provides a mechanism called Client Policies to enforce security require… | |
| CVE-2026-8830 | Low | 0.4% | 4.3 | A flaw was found in Keycloak. An authenticated user can bypass configured WebAut… | |
| CVE-2026-14209 | Low | 0.4% | 4.3 | A vulnerability was discovered in Keycloak's Admin UI extension that allows cert… | |
| CVE-2026-17048 | Low | 0.4% | 5.5 | A flaw was found in the Keycloak Admin REST API, which is used to manage securit… | |
| CVE-2026-9798 | Low | 0.3% | 4.3 | A flaw was found in Keycloak, an open-source identity and access management solu… | |
| CVE-2026-16103 | Low | 0.3% | 4.3 | A flaw was found in the keycloak-services component of Keycloak. This issue is a… | |
| CVE-2026-15943 | Low | 0.3% | 5.5 | A flaw was found in the Keycloak keycloak-services component, which handles the … | |
| CVE-2026-14613 | Low | 0.3% | 4.3 | A vulnerability was discovered in Keycloak's administrative interface that allow… | |
| CVE-2026-9689 | Low | 0.3% | 4.2 | A flaw was found in Keycloak, an open-source identity and access management solu… | |
| CVE-2026-14615 | Low | 0.3% | 4.3 | A flaw was found in the Fine-Grained Admin Permissions (FGAP) v2 implementation … | |
| CVE-2026-14614 | Low | 0.3% | 5.4 | A flaw was found in the ClientResource component of Keycloak's admin services wh… | |
| CVE-2026-15945 | Low | 0.3% | 4.3 | A flaw was found in the group search functionality of the Keycloak server's admi… | |
| CVE-2026-9087 | Low | 0.3% | 6.4 | A flaw was found in Keycloak. The cross-session verification proof is keyed only… | |
| CVE-2026-11986 | Low | 0.3% | 4.9 | A flaw was found in the admin-ui-ext component of Keycloak, which provides exten… | |
| CVE-2026-18571 | Low | 0.3% | 6.6 | A flaw was found in the user creation component of Keycloak when Fine-Grained Ad… | |
| CVE-2026-8922 | Low | 0.3% | 5.4 | A flaw was found in Keycloak. When both realm-level and client-level `notBefore`… | |
| CVE-2026-14781 | Low | 0.3% | 4.8 | A flaw exists in the org.keycloak.broker.oidc package where the OIDC broker inco… | |
| CVE-2026-18201 | Low | 0.3% | 5.5 | Keycloak provides a way to manage identity providers and organizations through i… | |
| CVE-2026-18573 | Low | 0.3% | 6.5 | A flaw was found in the keycloak-services component of Keycloak, which is used f… | |
| CVE-2026-2366 | Low | 0.3% | 3.1 | A flaw was found in Keycloak. An authorization bypass vulnerability in the Keycl… | |
| CVE-2026-16104 | Low | 0.3% | 4.3 | A flaw was found in the authentication configuration endpoint of the keycloak-se… | |
| CVE-2026-3429 | Low | 0.2% | 4.2 | A flaw was identified in the Account REST API of Keycloak that allows a user aut… | |
| CVE-2026-16105 | Low | 0.2% | 4.9 | A flaw was found in the RoleContainerResource component of Keycloak. The issue o… | |
| CVE-2026-18209 | Low | 0.2% | 3.4 | A flaw was found in the keycloak-services component of Keycloak, which handles O… | |
| CVE-2026-16071 | Low | 0.2% | 5.4 | A flaw was found in the LDAP storage provider of Keycloak, which is used to fede… | |
| CVE-2026-18215 | Low | 0.2% | 6.8 | Keycloak provides a way to let users log in using Microsoft accounts while restr… | |
| CVE-2026-18214 | Low | 0.2% | 6.8 | Keycloak allows users to log in using Google accounts and can be configured to o… | |
| CVE-2026-18207 | Low | 0.2% | 6.5 | A flaw was found in the client policy enforcement mechanism of Keycloak. The iss… | |
| CVE-2026-18572 | Low | 0.2% | 6.5 | Keycloak provides authorization services that allow administrators to restrict a… |
Page 1 of 2
Next →