漏洞总结 漏洞概述 漏洞编号: CVE-2026-8922 标题: org.keycloak/keycloak-services: keycloak: org.keycloak.protocol.oidc: Security flaw in org.keycloak/keycloak-services 状态: NEW 报告时间: 2026-05-18 14:51 UTC 修改时间: 2026-05-19 08:24 UTC 严重程度: medium 优先级: medium 组件: vulnerability 影响范围 产品: Security Response 操作系统: Linux 硬件: All 环境: unspecified 版本: unspecified 修复方案 修复版本: 未指定 克隆自: 未指定 最后关闭: 未指定 Embargoed: 未指定 漏洞描述 OIDC Introspection fails to honor realm-level notBefore revocation policies when a client-level notBefore value is also present, allowing revoked tokens to remain active. 附件 描述: OIDC Introspection fails to honor realm-level notBefore revocation policies when a client-level notBefore value is also present, allowing revoked tokens to remain active.