Keycloak
by Red Hat
Source repositories
CVEs (135)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-10734 | Low | 0.21 | 3.3 | 0.00 | Feb 11, 2021 | A vulnerability was found in keycloak in the way that the OIDC logout endpoint does not have CSRF protection. Versions shipped with Red Hat Fuse 7, Red Hat Single Sign-on 7, and Red Hat Openshift Application Runtimes are believed to be vulnerable. | ||
| CVE-2014-3655 | Med | 0.21 | 4.3 | 0.00 | Nov 13, 2019 | JBoss KeyCloak is vulnerable to soft token deletion via CSRF | ||
| CVE-2020-27826 | Med | 0.20 | 4.2 | 0.01 | May 28, 2021 | A flaw was found in Keycloak before version 12.0.0 where it is possible to update the user's metadata attributes using Account REST API. This flaw allows an attacker to change its own NameID attribute to impersonate the admin user for any particular application. | ||
| CVE-2020-10686 | Med | 0.20 | 4.1 | 0.01 | May 4, 2020 | A flaw was found in Keycloak version 8.0.2 and 9.0.0, and was fixed in Keycloak version 9.0.1, where a malicious user registers as oneself. The attacker could then use the remove devices form to post different credential IDs and possibly remove MFA devices for other users. | ||
| CVE-2025-5416 | Low | 0.18 | 2.7 | 0.00 | Jun 20, 2025 | A vulnerability has been identified in Keycloak that could lead to unauthorized information disclosure. While it requires an already authenticated user, the /admin/serverinfo endpoint can inadvertently provide sensitive environment information. | ||
| CVE-2020-1717 | Low | 0.18 | 2.7 | 0.01 | Feb 11, 2021 | A flaw was found in Keycloak 7.0.1. A logged in user can do an account email enumeration attack. | ||
| CVE-2019-3868 | Low | 0.18 | 3.8 | 0.01 | Apr 24, 2019 | Keycloak up to version 6.0.0 allows the end user token (access or id token JWT) to be used as the session cookie for browser sessions for OIDC. As a result an attacker with access to service provider backend could hijack user’s browser session. | ||
| CVE-2024-1722 | Low | 0.17 | 3.7 | 0.01 | Feb 29, 2024 | A flaw was found in Keycloak. In certain conditions, this issue may allow a remote unauthenticated attacker to block other accounts from logging in. | ||
| CVE-2016-8609 | Low | 0.17 | 3.7 | 0.02 | Aug 1, 2018 | It was found that the keycloak before 2.3.0 did not implement authentication flow correctly. An attacker could use this flaw to construct a phishing URL, from which he could hijack the user's session. This could lead to information disclosure, or permit further possible attacks. | ||
| CVE-2025-12150 | Low | 0.13 | 3.1 | 0.00 | Feb 27, 2026 | A flaw was found in Keycloak’s WebAuthn registration component. This vulnerability allows an attacker to bypass the configured attestation policy and register untrusted or forged authenticators via submission of an attestation object with fmt: "none", even when the realm is… | ||
| CVE-2026-9088 | Low | 0.11 | 2.7 | 0.00 | Jun 5, 2026 | A flaw was found in org.keycloak.services. An administrator with delegated access to read group memberships and users can bypass user profile permissions by accessing the group members endpoint. This allows the administrator to view user attributes that are explicitly configured… | ||
| CVE-2020-10770 | Med | 0.09 | 5.3 | 0.70 | Dec 15, 2020 | A flaw was found in Keycloak before 13.0.0, where it is possible to force the server to call out an unverified URL using the OIDC parameter request_uri. This flaw allows an attacker to use this parameter to execute a Server-side request forgery (SSRF) attack. | ||
| CVE-2026-9799 | Med | 0.00 | 4.6 | 0.00 | Jun 25, 2026 | A flaw was found in org.keycloak.authorization. An authenticated user with a granted User-Managed Access (UMA) permission ticket for one resource can exploit this by using a specific permission request prefix to bypass per-resource access control. This allows the user to gain… | ||
| CVE-2021-3513 | Hig | 0.00 | 7.5 | 0.01 | Aug 22, 2022 | A flaw was found in keycloak where a brute force attack is possible even when the permanent lockout feature is enabled. This is due to a wrong error message displayed when wrong credentials are entered. The highest threat from this vulnerability is to confidentiality. | ||
| CVE-2017-2582 | Med | 0.00 | 6.5 | 0.02 | Jul 26, 2018 | It was found that while parsing the SAML messages the StaxParserUtil class of keycloak before 2.5.1 replaces special strings for obtaining attribute values with system property. This could allow an attacker to determine values of system properties at the attacked system by… |
- risk 0.21cvss 3.3epss 0.00
A vulnerability was found in keycloak in the way that the OIDC logout endpoint does not have CSRF protection. Versions shipped with Red Hat Fuse 7, Red Hat Single Sign-on 7, and Red Hat Openshift Application Runtimes are believed to be vulnerable.
- risk 0.21cvss 4.3epss 0.00
JBoss KeyCloak is vulnerable to soft token deletion via CSRF
- risk 0.20cvss 4.2epss 0.01
A flaw was found in Keycloak before version 12.0.0 where it is possible to update the user's metadata attributes using Account REST API. This flaw allows an attacker to change its own NameID attribute to impersonate the admin user for any particular application.
- risk 0.20cvss 4.1epss 0.01
A flaw was found in Keycloak version 8.0.2 and 9.0.0, and was fixed in Keycloak version 9.0.1, where a malicious user registers as oneself. The attacker could then use the remove devices form to post different credential IDs and possibly remove MFA devices for other users.
- risk 0.18cvss 2.7epss 0.00
A vulnerability has been identified in Keycloak that could lead to unauthorized information disclosure. While it requires an already authenticated user, the /admin/serverinfo endpoint can inadvertently provide sensitive environment information.
- risk 0.18cvss 2.7epss 0.01
A flaw was found in Keycloak 7.0.1. A logged in user can do an account email enumeration attack.
- risk 0.18cvss 3.8epss 0.01
Keycloak up to version 6.0.0 allows the end user token (access or id token JWT) to be used as the session cookie for browser sessions for OIDC. As a result an attacker with access to service provider backend could hijack user’s browser session.
- risk 0.17cvss 3.7epss 0.01
A flaw was found in Keycloak. In certain conditions, this issue may allow a remote unauthenticated attacker to block other accounts from logging in.
- risk 0.17cvss 3.7epss 0.02
It was found that the keycloak before 2.3.0 did not implement authentication flow correctly. An attacker could use this flaw to construct a phishing URL, from which he could hijack the user's session. This could lead to information disclosure, or permit further possible attacks.
- risk 0.13cvss 3.1epss 0.00
A flaw was found in Keycloak’s WebAuthn registration component. This vulnerability allows an attacker to bypass the configured attestation policy and register untrusted or forged authenticators via submission of an attestation object with fmt: "none", even when the realm is…
- risk 0.11cvss 2.7epss 0.00
A flaw was found in org.keycloak.services. An administrator with delegated access to read group memberships and users can bypass user profile permissions by accessing the group members endpoint. This allows the administrator to view user attributes that are explicitly configured…
- risk 0.09cvss 5.3epss 0.70
A flaw was found in Keycloak before 13.0.0, where it is possible to force the server to call out an unverified URL using the OIDC parameter request_uri. This flaw allows an attacker to use this parameter to execute a Server-side request forgery (SSRF) attack.
- risk 0.00cvss 4.6epss 0.00
A flaw was found in org.keycloak.authorization. An authenticated user with a granted User-Managed Access (UMA) permission ticket for one resource can exploit this by using a specific permission request prefix to bypass per-resource access control. This allows the user to gain…
- risk 0.00cvss 7.5epss 0.01
A flaw was found in keycloak where a brute force attack is possible even when the permanent lockout feature is enabled. This is due to a wrong error message displayed when wrong credentials are entered. The highest threat from this vulnerability is to confidentiality.
- risk 0.00cvss 6.5epss 0.02
It was found that while parsing the SAML messages the StaxParserUtil class of keycloak before 2.5.1 replaces special strings for obtaining attribute values with system property. This could allow an attacker to determine values of system properties at the attacked system by…
Page 7 of 7