VYPR

Keycloak

by Red Hat

Source repositories

CVEs (129)

  • CVE-2020-1717LowFeb 11, 2021
    risk 0.18cvss 2.7epss 0.01

    A flaw was found in Keycloak 7.0.1. A logged in user can do an account email enumeration attack.

  • CVE-2024-1722LowFeb 29, 2024
    risk 0.17cvss 3.7epss 0.01

    A flaw was found in Keycloak. In certain conditions, this issue may allow a remote unauthenticated attacker to block other accounts from logging in.

  • CVE-2016-8609LowAug 1, 2018
    risk 0.17cvss 3.7epss 0.02

    It was found that the keycloak before 2.3.0 did not implement authentication flow correctly. An attacker could use this flaw to construct a phishing URL, from which he could hijack the user's session. This could lead to information disclosure, or permit further possible attacks.

  • CVE-2025-12150LowFeb 27, 2026
    risk 0.13cvss 3.1epss 0.00

    A flaw was found in Keycloak’s WebAuthn registration component. This vulnerability allows an attacker to bypass the configured attestation policy and register untrusted or forged authenticators via submission of an attestation object with fmt: "none", even when the realm is…

  • CVE-2026-9088LowJun 5, 2026
    risk 0.11cvss 2.7epss 0.00

    A flaw was found in org.keycloak.services. An administrator with delegated access to read group memberships and users can bypass user profile permissions by accessing the group members endpoint. This allows the administrator to view user attributes that are explicitly configured…

  • CVE-2020-10770MedDec 15, 2020
    risk 0.09cvss 5.3epss 0.70

    A flaw was found in Keycloak before 13.0.0, where it is possible to force the server to call out an unverified URL using the OIDC parameter request_uri. This flaw allows an attacker to use this parameter to execute a Server-side request forgery (SSRF) attack.

  • CVE-2026-9799MedJun 25, 2026
    risk 0.00cvss 4.6epss 0.00

    A flaw was found in org.keycloak.authorization. An authenticated user with a granted User-Managed Access (UMA) permission ticket for one resource can exploit this by using a specific permission request prefix to bypass per-resource access control. This allows the user to gain…

  • CVE-2021-3513HigAug 22, 2022
    risk 0.00cvss 7.5epss 0.01

    A flaw was found in keycloak where a brute force attack is possible even when the permanent lockout feature is enabled. This is due to a wrong error message displayed when wrong credentials are entered. The highest threat from this vulnerability is to confidentiality.

  • CVE-2017-2582MedJul 26, 2018
    risk 0.00cvss 6.5epss 0.02

    It was found that while parsing the SAML messages the StaxParserUtil class of keycloak before 2.5.1 replaces special strings for obtaining attribute values with system property. This could allow an attacker to determine values of system properties at the attacked system by…

Page 7 of 7