Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Red Hat Build of Keycloak — Vulnerabilities & Security Advisories 39

All 39 CVE vulnerabilities found in Red Hat Build of Keycloak, with AI-generated Chinese analysis, references, and POCs.

This page documents Common Weakness Enumeration vulnerabilities associated with the Red Hat Build of Keycloak product. It aggregates security data to help users monitor and address potential risks within this specific identity and access management solution. The collection includes vulnerability records for the Red Hat Build of Keycloak, covering a comprehensive historical time range to ensure visibility into past and present security issues. Users can leverage this resource to track vendor-specific advisories issued by Red Hat, gain a deeper understanding of specific weakness classes such as authentication flaws or configuration errors, and look up the complete vulnerability history of the product over time. This approach allows security teams to contextualize individual findings within the broader ecosystem of the software, facilitating more informed risk management decisions. By centralizing this information, the page serves as a reference point for identifying patterns in security defects, assessing the impact of known issues, and prioritizing remediation efforts based on the severity and availability of patches. The data is organized to support efficient review, enabling stakeholders to quickly locate relevant details without sifting through fragmented sources. This consolidated view aids in maintaining the integrity and security posture of deployments that rely on the Red Hat Build of Keycloak, ensuring that administrators are aware of the latest security developments and historical context necessary for robust system protection.

Vendor: Red Hat

CVE IDTitleCVSSSeverityPublished
CVE-2026-18967 Keycloak-services: keycloak-services: saml onetimeuse assertion replay in idp-initiated broker flow CWE-294 6.4 Medium2026-08-06
CVE-2026-18569 Keycloak-services: keycloak-services: oidc backchannel logout accepts unsigned forged logout tokens CWE-347 3.7 Low2026-08-04
CVE-2026-18573 Keycloak-services: keycloak-services: client access-type policy condition bypass during client update CWE-862 6.5 Medium2026-08-02
CVE-2026-18572 Keycloak-services: keycloak-services: uma claim token can override authorization time-policy evaluation attributes CWE-863 6.5 Medium2026-08-02
CVE-2026-18571 Keycloak-services: keycloak-services: fgap v2 group assignment bypass during user creation CWE-862 6.6 Medium2026-08-02
CVE-2026-18570 Keycloak-services: keycloak-services: full-scope-disabled client policy validation bypass via omitted fullscopeallowed CWE-862 5.4 Medium2026-08-02
CVE-2026-18209 Keycloak-services: keycloak-services: oidc redirect_uri fragment bypass in http parameter pollution check CWE-1288 3.4 Low2026-07-31
CVE-2026-18206 Keycloak-services: keycloak-services: client policy source-host wildcard domain matching bypass CWE-20 3.7 Low2026-07-31
CVE-2026-18203 Keycloak-services: keycloak-services: group policy extendchildren matches sibling group path prefixes CWE-863 6.5 Medium2026-07-31
CVE-2026-18214 Keycloak-services: keycloak-services: google external access-token exchange bypasses hosted-domain restriction CWE-862 6.8 Medium2026-07-31
CVE-2026-18211 Keycloak-services: keycloak-services: secure-client-uris policy bypass via localhost-prefixed domains CWE-20 4.2 Medium2026-07-31
CVE-2026-18208 Keycloak-services: keycloak-services: inactive out-of-audience token introspection leaks signed jwt claim CWE-862 6.5 Medium2026-07-31
CVE-2026-16105 Keycloak-services: keycloak-services: missing per-role authorization on rolecontainerresource composite endpoints 4.9 Medium2026-07-31
CVE-2026-18215 Keycloak-services: keycloak-services: microsoft external access-token exchange bypasses configured tenant CWE-287 6.8 Medium2026-07-31
CVE-2026-18217 Keycloak-services: keycloak-services: saml http-redirect binding response preserves query string leading to parameter pollution CWE-20 3.4 Low2026-07-31
CVE-2026-18218 Keycloak-services: keycloak-services: client not-before revocation ignored when realm not-before is older but nonzero CWE-862 4.2 Medium2026-07-31
CVE-2026-18201 Keycloak-services: keycloak-services: generic identity-provider creation can bind brokers to organizations without manage-organizations CWE-862 5.5 Medium2026-07-29
CVE-2026-18207 Keycloak-services: keycloak-services: client policy source-group condition bypass via duplicate group name matching CWE-285 6.5 Medium2026-07-29
CVE-2026-17059 Keycloak-services: keycloak-services: information disclosure via role-users endpoint bypasses per-user view filter CWE-639 6.5 Medium2026-07-24
CVE-2026-17048 Keycloak-services: keycloak-services: vault-resolved rotated client secrets leaked via admin rest api CWE-200 5.5 Medium2026-07-24
CVE-2026-16104 Keycloak-services: keycloak-services: authenticator config endpoint exposes raw recaptcha secrets to view-only admins 4.3 Medium2026-07-17
CVE-2026-16103 Keycloak-services: keycloak-services: incomplete fix for ciba brute-force lockout bypass at token redemption 4.3 Medium2026-07-17
CVE-2026-16106 Keycloak-services: keycloak-services: incorrect authorization in admin role-composite deletion allows delegated admin to remove privileged child roles 4.9 Medium2026-07-17
CVE-2026-16108 Keycloak-services: keycloak-services: realm default-group reads disclose hidden groups under fgap v2 4.3 Medium2026-07-17
CVE-2026-16093 Keycloak-services: keycloak-services: required signed-jwt assertion policy can be bypassed with unsigned assertion headers CWE-807 5.4 Medium2026-07-17
CVE-2026-16089 Keycloak-services: keycloak-services: authorization codes can be retargeted to another client session 5.4 Medium2026-07-17
CVE-2026-16072 Keycloak-services: keycloak-services: organization invitation link exposure allows unauthorized member creation 4.9 Medium2026-07-17
CVE-2026-15943 Keycloak-services: keycloak-services: oidc idp update reuses masked client secret after token url change CWE-1288 5.5 Medium2026-07-17
CVE-2026-15945 Keycloak-services: keycloak-services: group hierarchy search discloses hidden parent groups under fgap v2 CWE-639 4.3 Medium2026-07-16
CVE-2026-14781 Keycloak-services: keycloak-services: oidc email_verified claim incorrectly applied to userinfo email CWE-1288 4.8 Medium2026-07-05

All 39 known CVE vulnerabilities affecting Red Hat Build of Keycloak with full Chinese analysis, references, and POCs where available.