Low severityGHSA Advisory· Published Feb 2, 2026· Updated Jul 24, 2026
CVE-2026-1518
CVE-2026-1518
Description
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. After further review by the Keycloak project and Red Hat, the reported SSRF via client registration/backchannel notification URIs was determined not to constitute a security vulnerability. The reported behavior is expected administrator-controlled functionality, and Keycloak provides documented mitigations through Client Policies, including the Secure Client URIs Pattern executor. Therefore, this CVE has been rejected.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.keycloak:keycloak-parentMaven | <= 26.5.2 | — |
Affected products
2Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.