Keycloak
by Red Hat
Source repositories
CVEs (129)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-1717 | Low | 0.18 | 2.7 | 0.01 | Feb 11, 2021 | A flaw was found in Keycloak 7.0.1. A logged in user can do an account email enumeration attack. | ||
| CVE-2024-1722 | Low | 0.17 | 3.7 | 0.01 | Feb 29, 2024 | A flaw was found in Keycloak. In certain conditions, this issue may allow a remote unauthenticated attacker to block other accounts from logging in. | ||
| CVE-2016-8609 | Low | 0.17 | 3.7 | 0.02 | Aug 1, 2018 | It was found that the keycloak before 2.3.0 did not implement authentication flow correctly. An attacker could use this flaw to construct a phishing URL, from which he could hijack the user's session. This could lead to information disclosure, or permit further possible attacks. | ||
| CVE-2025-12150 | Low | 0.13 | 3.1 | 0.00 | Feb 27, 2026 | A flaw was found in Keycloak’s WebAuthn registration component. This vulnerability allows an attacker to bypass the configured attestation policy and register untrusted or forged authenticators via submission of an attestation object with fmt: "none", even when the realm is… | ||
| CVE-2026-9088 | Low | 0.11 | 2.7 | 0.00 | Jun 5, 2026 | A flaw was found in org.keycloak.services. An administrator with delegated access to read group memberships and users can bypass user profile permissions by accessing the group members endpoint. This allows the administrator to view user attributes that are explicitly configured… | ||
| CVE-2020-10770 | Med | 0.09 | 5.3 | 0.70 | Dec 15, 2020 | A flaw was found in Keycloak before 13.0.0, where it is possible to force the server to call out an unverified URL using the OIDC parameter request_uri. This flaw allows an attacker to use this parameter to execute a Server-side request forgery (SSRF) attack. | ||
| CVE-2026-9799 | Med | 0.00 | 4.6 | 0.00 | Jun 25, 2026 | A flaw was found in org.keycloak.authorization. An authenticated user with a granted User-Managed Access (UMA) permission ticket for one resource can exploit this by using a specific permission request prefix to bypass per-resource access control. This allows the user to gain… | ||
| CVE-2021-3513 | Hig | 0.00 | 7.5 | 0.01 | Aug 22, 2022 | A flaw was found in keycloak where a brute force attack is possible even when the permanent lockout feature is enabled. This is due to a wrong error message displayed when wrong credentials are entered. The highest threat from this vulnerability is to confidentiality. | ||
| CVE-2017-2582 | Med | 0.00 | 6.5 | 0.02 | Jul 26, 2018 | It was found that while parsing the SAML messages the StaxParserUtil class of keycloak before 2.5.1 replaces special strings for obtaining attribute values with system property. This could allow an attacker to determine values of system properties at the attacked system by… |
- risk 0.18cvss 2.7epss 0.01
A flaw was found in Keycloak 7.0.1. A logged in user can do an account email enumeration attack.
- risk 0.17cvss 3.7epss 0.01
A flaw was found in Keycloak. In certain conditions, this issue may allow a remote unauthenticated attacker to block other accounts from logging in.
- risk 0.17cvss 3.7epss 0.02
It was found that the keycloak before 2.3.0 did not implement authentication flow correctly. An attacker could use this flaw to construct a phishing URL, from which he could hijack the user's session. This could lead to information disclosure, or permit further possible attacks.
- risk 0.13cvss 3.1epss 0.00
A flaw was found in Keycloak’s WebAuthn registration component. This vulnerability allows an attacker to bypass the configured attestation policy and register untrusted or forged authenticators via submission of an attestation object with fmt: "none", even when the realm is…
- risk 0.11cvss 2.7epss 0.00
A flaw was found in org.keycloak.services. An administrator with delegated access to read group memberships and users can bypass user profile permissions by accessing the group members endpoint. This allows the administrator to view user attributes that are explicitly configured…
- risk 0.09cvss 5.3epss 0.70
A flaw was found in Keycloak before 13.0.0, where it is possible to force the server to call out an unverified URL using the OIDC parameter request_uri. This flaw allows an attacker to use this parameter to execute a Server-side request forgery (SSRF) attack.
- risk 0.00cvss 4.6epss 0.00
A flaw was found in org.keycloak.authorization. An authenticated user with a granted User-Managed Access (UMA) permission ticket for one resource can exploit this by using a specific permission request prefix to bypass per-resource access control. This allows the user to gain…
- risk 0.00cvss 7.5epss 0.01
A flaw was found in keycloak where a brute force attack is possible even when the permanent lockout feature is enabled. This is due to a wrong error message displayed when wrong credentials are entered. The highest threat from this vulnerability is to confidentiality.
- risk 0.00cvss 6.5epss 0.02
It was found that while parsing the SAML messages the StaxParserUtil class of keycloak before 2.5.1 replaces special strings for obtaining attribute values with system property. This could allow an attacker to determine values of system properties at the attacked system by…
Page 7 of 7