| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat build of Keycloak 26.4 | 26.4.14-1< * | unaffected |
26.4-22< * | unaffected | ||
26.4-22< * | unaffected | ||
| Red Hat | Red Hat build of Keycloak 26.4.14 | any | unaffected |
any | unaffected | ||
| Red Hat | Red Hat build of Keycloak 26.6 | 26.6.5-1< * | unaffected |
26.6-11< * | unaffected | ||
26.6-11< * | unaffected | ||
| Red Hat | Red Hat build of Keycloak 26.6.5 | any | unaffected |
any | unaffected | ||
any | unaffected | ||
| Red Hat | Red Hat Data Grid 8 | any | unaffected |
| Red Hat | Red Hat JBoss Enterprise Application Platform Expansion Pack | any | unaffected |
| Red Hat | Red Hat Single Sign-On 7 | any | unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat build of Keycloak 26.4 | 26.4.14-1 ~ * | cpe:/a:redhat:build_keycloak:26.4::el9 | |
| Red Hat | Red Hat build of Keycloak 26.4 | 26.4-22 ~ * | cpe:/a:redhat:build_keycloak:26.4::el9 | |
| Red Hat | Red Hat build of Keycloak 26.4 | 26.4-22 ~ * | cpe:/a:redhat:build_keycloak:26.4::el9 | |
| Red Hat | Red Hat build of Keycloak 26.4.14 | - | cpe:/a:redhat:build_keycloak:26.4::el9 | |
| Red Hat | Red Hat build of Keycloak 26.4.14 | - | cpe:/a:redhat:build_keycloak:26.4::el9 | |
| Red Hat | Red Hat build of Keycloak 26.6 | 26.6.5-1 ~ * | cpe:/a:redhat:build_keycloak:26.6::el9 | |
| Red Hat | Red Hat build of Keycloak 26.6 | 26.6-11 ~ * | cpe:/a:redhat:build_keycloak:26.6::el9 | |
| Red Hat | Red Hat build of Keycloak 26.6 | 26.6-11 ~ * | cpe:/a:redhat:build_keycloak:26.6::el9 | |
| Red Hat | Red Hat build of Keycloak 26.6.5 | - | cpe:/a:redhat:build_keycloak:26.6::el9 | |
| Red Hat | Red Hat build of Keycloak 26.6.5 | - | cpe:/a:redhat:build_keycloak:26.6::el9 | |
| Red Hat | Red Hat build of Keycloak 26.6.5 | - | cpe:/a:redhat:build_keycloak:26.6::el9 | |
| Red Hat | Red Hat Data Grid 8 | - | cpe:/a:redhat:jboss_data_grid:8 | |
| Red Hat | Red Hat JBoss Enterprise Application Platform Expansion Pack | - | cpe:/a:redhat:jbosseapxp | |
| Red Hat | Red Hat Single Sign-On 7 | - | cpe:/a:redhat:red_hat_single_sign_on:7 |
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-10090 | 9.9 CRITICAL | Multicluster-operators-subscription: multicluster-operators-subscription: namespace edit u |
| CVE-2026-10059 | 9.1 CRITICAL | Cluster-curator-controller: cluster-curator-controller: namespace admin can escalate to cl |
| CVE-2026-15572 | 8.8 HIGH | Keycloak-services: keycloak-services: dcr protocol mapper type-swap policy bypass allows p |
| CVE-2026-16102 | 8.1 HIGH | Keycloak-services: keycloak-services: default dcr policy allows role forgery via user prop |
| CVE-2026-15573 | 8.1 HIGH | Keycloak-services: keycloak-services: authorization bypass via unnormalized uri matching i |
| CVE-2026-16442 | 7.4 HIGH | Keycloak-services: keycloak-services: saml idp-initiated broker login bypasses link-only r |
| CVE-2026-16443 | 7.4 HIGH | Keycloak-services: keycloak-services: saml broker metadata import disables response signat |
| CVE-2026-71226 | 7.3 HIGH | Libkcapi: memory corruption via uncanceled aio requests on error in libkcapi's one-shot ai |
| CVE-2026-49331 | 6.5 MEDIUM | Openshift/oauth-proxy: openshift/oauth-proxy: unauthenticated identity header injection on |
| CVE-2026-16100 | 6.5 MEDIUM | Keycloak-services: keycloak-services: unbounded metric cardinality in user event metrics v |
| CVE-2026-71225 | 6.5 MEDIUM | Libkcapi: iv reuse in libkcapi one-shot symmetric cipher chunking causes cipher state rese |
| CVE-2026-44605 | 5.5 MEDIUM | Rpm: heap buffer overflow in ndb slot table parsing |
| CVE-2026-71227 | 5.1 MEDIUM | Libkcapi: infinite loop denial of service in libkcapi _kcapi_aio_read_all() due to unhandl |
No comments yet