VYPR

keycloak-services

by Red Hat

CVEs (8)

  • CVE-2026-16443HigAug 5, 2026
    risk 0.48cvss 7.4epss 0.00

    A flaw was found in the SAML metadata import functionality of the keycloak-services component, which is the core engine for identity brokering in Red Hat Build of Keycloak. When importing identity provider metadata that lacks specific usage attributes for keys, the system…

  • CVE-2026-79651HigSep 16, 2026
    risk 0.42cvss 7.5epss 0.01

    A flaw was found in the theme localization endpoints of the keycloak-services component, which is the core service responsible for authentication flows and theme management in Keycloak. The issue occurs because the system accepts arbitrary locale tags from unauthenticated…

  • CVE-2026-18208MedJul 31, 2026
    risk 0.42cvss 6.5epss 0.00

    A flaw was found in the OIDC token introspection endpoint of the keycloak-services component. Keycloak is an open-source identity and access management solution used to secure modern applications and services. The issue occurs when a confidential client, configured to receive…

  • CVE-2026-79652MedAug 25, 2026
    risk 0.38cvss 5.9epss 0.00

    A flaw was found in the JWT Bearer authorization grant implementation within the keycloak-services component of Red Hat Build of Keycloak. This component handles various OAuth2 and OpenID Connect grant types used for issuing access tokens. The issue occurs because the JWT Bearer…

  • CVE-2026-18570MedAug 2, 2026
    risk 0.35cvss 5.4epss 0.00

    A flaw was found in the full-scope-disabled client-policy executor within the keycloak-services component. This component is responsible for enforcing security policies during client registration and configuration in Red Hat Build of Keycloak. The issue occurs because the…

  • CVE-2026-19607MedSep 16, 2026
    risk 0.34cvss 5.3epss 0.01

    A flaw was found in the first-broker-login flow of the keycloak-services component. This component handles the initial authentication and account linking when a user logs in via an external identity provider. The issue allows an attacker to register a matching username on an…

  • CVE-2026-19729MedSep 9, 2026
    risk 0.32cvss 4.9epss 0.00

    A flaw was found in the key provider component of the keycloak-services library, which is the core engine for the Red Hat Build of Keycloak. The issue occurs because a previous fix for path probing was incomplete, allowing a realm administrator to still submit arbitrary…

  • CVE-2026-18569LowAug 4, 2026
    risk 0.24cvss 3.7epss 0.00

    A flaw was found in the backchannel logout endpoint of the keycloak-services component, which is part of the Red Hat Build of Keycloak. This component handles authentication and session management for applications. The issue occurs when an OIDC identity provider is configured to…