VYPR

Keycloak

by Keycloak

Source repositories

CVEs (129)

  • CVE-2021-20202HigMay 12, 2021
    risk 0.47cvss 7.3epss 0.00

    A flaw was found in keycloak. Directories can be created prior to the Java process creating them in the temporary directory, but with wider user permissions, allowing the attacker to have access to the contents that keycloak stores in this directory. The highest threat from this…

  • CVE-2026-2603HigMar 18, 2026
    risk 0.46cvss 8.1epss 0.00

    A flaw was found in Keycloak. A remote attacker could bypass security controls by sending a valid SAML response from an external Identity Provider (IdP) to the Keycloak SAML endpoint for IdP-initiated broker logins. This allows the attacker to complete broker logins even when…

  • CVE-2025-3501HigApr 29, 2025
    risk 0.46cvss 8.2epss 0.00

    A flaw was found in Keycloak. By setting a verification policy to 'ALL', the trust store certificate verification is skipped, which is unintended.

  • CVE-2021-3461HigApr 1, 2022
    risk 0.46cvss 7.1epss 0.00

    A flaw was found in keycloak where keycloak may fail to logout user session if the logout request comes from external SAML identity provider and Principal Type is set to Attribute [Name].

  • CVE-2024-10039higNov 25, 2024
    risk 0.45cvss epss 0.00

    A vulnerability was found in Keycloak. Deployments of Keycloak with a reverse proxy not using pass-through termination of TLS, with mTLS enabled, are affected. This issue may allow an attacker on the local network to authenticate as any user or client that leverages mTLS as the…

  • CVE-2026-18215MedJul 31, 2026
    risk 0.44cvss 6.8epss 0.00

    Keycloak provides a way to let users log in using Microsoft accounts while restricting access to a specific organization (tenant). A flaw was discovered where this restriction is ignored when using the token exchange feature. This means an attacker with a valid Microsoft token…

  • CVE-2026-18214MedJul 31, 2026
    risk 0.44cvss 6.8epss 0.00

    Keycloak allows users to log in using Google accounts and can be configured to only allow users from specific Google Workspace domains. A flaw was found where the token exchange feature, which allows swapping a Google token for a Keycloak token, does not check these domain…

  • CVE-2021-20262MedMar 9, 2021
    risk 0.44cvss 6.8epss 0.00

    A flaw was found in Keycloak 12.0.0 where re-authentication does not occur while updating the password. This flaw allows an attacker to take over an account if they can obtain temporary, physical access to a user’s browser. The highest threat from this vulnerability is to…

  • CVE-2026-18571MedAug 2, 2026
    risk 0.43cvss 6.6epss 0.00

    A flaw was found in the user creation component of Keycloak when Fine-Grained Admin Permissions V2 (FGAP V2) is enabled. This issue allows a sub-administrator with permission to create users to add those users to any group, even groups the sub-administrator is not authorized to…

  • CVE-2026-18967MedAug 6, 2026
    risk 0.42cvss 6.4epss 0.00

    A flaw was found in the SAML broker component of Keycloak, an identity and access management solution. When configured as a SAML broker using the IdP-Initiated flow, Keycloak fails to enforce the OneTimeUse condition in SAML assertions. This allows an attacker who captures a…

  • CVE-2026-18572MedAug 2, 2026
    risk 0.42cvss 6.5epss 0.00

    Keycloak provides authorization services that allow administrators to restrict access to resources based on time policies (for example, only allowing access during business hours). A flaw was discovered where a user can include a fake time value in their authorization request…

  • CVE-2026-18203MedJul 31, 2026
    risk 0.42cvss 6.5epss 0.00

    A flaw was found in the group policy evaluation logic of Keycloak, an identity and access management solution. When a group policy is set to extend permissions to child groups, the system incorrectly uses a simple text-based prefix check to verify group membership. This allows a…

  • CVE-2026-18207MedJul 29, 2026
    risk 0.42cvss 6.5epss 0.00

    A flaw was found in the client policy enforcement mechanism of Keycloak. The issue occurs when the system checks group membership by name instead of a unique identifier. An attacker with client management privileges could bypass security policies by joining a group with a…

  • CVE-2026-4629MedJun 30, 2026
    risk 0.42cvss 6.5epss 0.00

    A flaw was found in Keycloak. A highly privileged user with `manage-clients` permission can exploit this vulnerability by injecting a hardcoded role mapper into any client. This action allows the user to bypass existing scope restrictions and inject the `realm-admin` role into…

  • CVE-2026-12388MedJun 30, 2026
    risk 0.42cvss 6.5epss 0.00

    A flaw was found in the Identity Provider (IdP) mapper component of Keycloak, which is used to manage how user information from external services is mapped to Keycloak users. An administrator with limited permissions to manage identity providers can exploit this flaw by creating…

  • CVE-2026-7307HigMay 19, 2026
    risk 0.42cvss 7.5epss 0.01

    A flaw was found in Keycloak. A remote, unauthenticated attacker can send a specially crafted XML input to the Security Assertion Markup Language (SAML) endpoint. This malicious input can cause high CPU usage and worker thread starvation, leading to a Denial of Service (DoS)…

  • CVE-2022-2232HigNov 14, 2024
    risk 0.42cvss 7.5epss 0.01

    A flaw was found in the Keycloak package. This flaw allows an attacker to utilize an LDAP injection to bypass the username lookup or potentially perform other malicious actions.

  • CVE-2023-1664MedMay 26, 2023
    risk 0.42cvss 6.5epss 0.00

    A flaw was found in Keycloak. This flaw depends on a non-default configuration "Revalidate Client Certificate" to be enabled and the reverse proxy is not validating the certificate before Keycloak. Using this method an attacker may choose the certificate which will be validated…

  • CVE-2021-3632HigAug 26, 2022
    risk 0.42cvss 7.5epss 0.01

    A flaw was found in Keycloak. This vulnerability allows anyone to register a new security device or key when there is not a device already registered for any user by using the WebAuthn password-less login flow.

  • CVE-2021-20222HigMar 23, 2021
    risk 0.42cvss 7.5epss 0.01

    A flaw was found in keycloak. The new account console in keycloak can allow malicious code to be executed using the referrer URL. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Page 2 of 7