Low severity3.4NVD Advisory· Published Jul 31, 2026· Updated Aug 7, 2026
CVE-2026-18209
CVE-2026-18209
Description
A flaw was found in the keycloak-services component of Keycloak, which handles OpenID Connect (OIDC) authentication flows. The issue occurs because the security check designed to prevent HTTP parameter pollution only inspects the query portion of a redirect URL and ignores the fragment portion. When a client is configured with a wildcard redirect URI, an attacker can use this to inject duplicate security parameters into the login response. If a client application is not configured correctly, it might trust the attacker's injected data instead of the real security information from Keycloak, leading to session fixation or account confusion.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:redhat:build_of_keycloak:-:*:*:*:-:*:*:*
Patches
Vulnerability mechanics
References
2- access.redhat.com/security/cve/CVE-2026-18209nvdVendor Advisory
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingVendor Advisory
News mentions
1- Keycloak Services: Nine Auth and Policy Bypass Vulnerabilities Disclosed TogetherVypr Intelligence · Jul 28, 2026