VYPR

Vendor CVEs

Keycloak

All CVEs

141 total · sorted by risk
  • CVE-2019-14910CriDec 5, 2019
    risk 0.64cvss 9.8epss 0.01

    A vulnerability was found in keycloak 7.x, when keycloak is configured with LDAP user federation and StartTLS is used instead of SSL/TLS from the LDAP server (ldaps), in this case user authentication succeeds even if invalid password has entered.

  • CVE-2017-7474CriMay 12, 2017
    risk 0.64cvss 9.8epss 0.03

    It was found that the Keycloak Node.js adapter 2.5 - 3.0 did not handle invalid tokens correctly. An attacker could use this flaw to bypass authentication and gain access to restricted information, or to possibly conduct further attacks.

  • CVE-2022-4361CriJul 7, 2023
    risk 0.58cvss 10.0epss 0.01

    Keycloak, an open-source identity and access management solution, has a cross-site scripting (XSS) vulnerability in the SAML or OIDC providers. The vulnerability can allow an attacker to execute malicious scripts by setting the AssertionConsumerServiceURL value or the…

  • CVE-2026-15572HigAug 5, 2026
    risk 0.57cvss 8.8epss 0.00

    A flaw was found in Keycloak's Dynamic Client Registration (DCR) security policy management. The "Allowed Protocol Mapper Types" policy, which restricts which types of data mappers a client can use, fails to re-validate the mapper type during a client update if the mapper's…

  • CVE-2023-4918HigSep 12, 2023
    risk 0.57cvss 8.8epss 0.00

    A flaw was found in the Keycloak package, more specifically org.keycloak.userprofile. When a user registers itself through registration flow, the "password" and "password-confirm" field from the form will occur as regular user attributes. All users and clients with proper rights…

  • CVE-2022-1245CriJul 8, 2022
    risk 0.57cvss 9.8epss 0.01

    A privilege escalation flaw was found in the token exchange feature of keycloak. Missing authorization allows a client application holding a valid access token to exchange tokens for any target client by passing the client_id of the target. This could allow a client to gain…

  • CVE-2021-4133HigJan 25, 2022
    risk 0.57cvss 8.8epss 0.01

    A flaw was found in Keycloak in versions from 12.0.0 and before 15.1.1 which allows an attacker with any existing user account to create new default user accounts via the administrative REST API even when new user registration is disabled.

  • CVE-2021-20195CriMay 28, 2021
    risk 0.55cvss 9.6epss 0.01

    A flaw was found in keycloak in versions before 13.0.0. A Self Stored XSS attack vector escalating to a complete account takeover is possible due to user-supplied data fields not being properly encoded and Javascript code being used to process the data. The highest threat from…

  • CVE-2019-14909HigDec 4, 2019
    risk 0.54cvss 8.3epss 0.01

    A vulnerability was found in Keycloak 7.x where the user federation LDAP bind type is none (LDAP anonymous bind), any password, invalid or valid will be accepted.

  • CVE-2026-15573HigAug 5, 2026
    risk 0.53cvss 8.1epss 0.00

    A flaw was found in Keycloak's Authorization Services. The component responsible for matching request paths to security policies (PathMatcher) does not properly normalize URIs before comparison. By adding extra characters like a trailing slash or matrix parameters to a URL, an…

  • CVE-2026-1609HigJul 16, 2026
    risk 0.53cvss 8.1epss 0.01

    A flaw was found in Keycloak. When the JSON Web Token (JWT) authorization grant preview feature is enabled and a user account is disabled, Keycloak fails to validate the user’s disabled status during JWT authorization grant processing. A remote attacker with low privileges can…

  • CVE-2026-9800HigJun 25, 2026
    risk 0.53cvss 8.1epss 0.00

    A flaw was found in Keycloak Policy Enforcer. This vulnerability allows any authenticated user to bypass all authorization policies, including role, scope, and User-Managed Access (UMA) permission checks. By including the configured access-denied page path within a request URL,…

  • CVE-2020-14389HigNov 17, 2020
    risk 0.53cvss 8.1epss 0.01

    It was found that Keycloak before version 12.0.0 would permit a user with only view-profile role to manage the resources in the new account console, allowing access and modification of data the user was not intended to have.

  • CVE-2026-9099HigJun 25, 2026
    risk 0.50cvss 7.7epss 0.00

    A flaw was found in Keycloak. A missing authorization check in the GroupResource.addChild() endpoint within the Admin REST API allows an authenticated user with limited administrative privileges to reparent any existing group. When Fine-Grained Admin Permissions v2 (FGAPv2) is…

  • CVE-2014-3709HigOct 18, 2017
    risk 0.50cvss 8.8epss 0.01

    The org.keycloak.services.resources.SocialResource.callback method in JBoss KeyCloak before 1.0.3.Final allows remote attackers to conduct cross-site request forgery (CSRF) attacks by leveraging lack of CSRF protection.

  • CVE-2025-11419HigDec 23, 2025
    risk 0.49cvss 7.5epss 0.01

    A flaw was found in Keycloak. This vulnerability allows an unauthenticated remote attacker to cause a denial of service (DoS) by repeatedly initiating TLS 1.2 client-initiated renegotiation requests to exhaust server CPU resources, making the service unavailable.

  • CVE-2014-3651HigDec 29, 2017
    risk 0.49cvss 7.5epss 0.02

    JBoss KeyCloak before 1.0.3.Final allows remote attackers to cause a denial of service (resource consumption) via a large value in the size parameter to auth/qrcode, related to QR code generation.

  • CVE-2017-12159HigOct 26, 2017
    risk 0.49cvss 7.5epss 0.03

    It was found that the cookie used for CSRF prevention in Keycloak was not unique to each session. An attacker could use this flaw to gain access to an authenticated user session, leading to possible information disclosure or further attacks.

  • CVE-2026-16442HigAug 5, 2026
    risk 0.48cvss 7.4epss 0.00

    A flaw was found in the SAML broker component of Keycloak, which is used to manage identity federation and user authentication. The issue occurs because the IdP-initiated Single Sign-On endpoint fails to check if a provider is restricted to account linking only. This allows an…

  • CVE-2020-14359HigFeb 23, 2021
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in all versions of Keycloak Gatekeeper, where on using lower case HTTP headers (via cURL) an attacker can bypass our Gatekeeper. Lower case headers are also accepted by some webservers (e.g. Jetty). This means there is no protection when we put a…

  • CVE-2026-9086HigJun 25, 2026
    risk 0.47cvss 7.3epss 0.00

    A flaw was found in Keycloak. A remote attacker with administrative privileges, specifically those with `manage-client` permission or access to client registration endpoints, could bypass client Uniform Resource Identifier (URI) validation. This is achieved by registering a…

  • CVE-2026-11577HigJun 8, 2026
    risk 0.47cvss 7.2epss 0.00

    A flaw was found in Keycloak. A limited administrator can exploit an improper access control vulnerability in the POST /admin/realms/{realm}/partialImport endpoint. This allows them to bypass Fine-Grained Admin Permissions (FGAP) and escalate their privileges to a full realm…

  • CVE-2021-20202HigMay 12, 2021
    risk 0.47cvss 7.3epss 0.00

    A flaw was found in keycloak. Directories can be created prior to the Java process creating them in the temporary directory, but with wider user permissions, allowing the attacker to have access to the contents that keycloak stores in this directory. The highest threat from this…

  • CVE-2026-2603HigMar 18, 2026
    risk 0.46cvss 8.1epss 0.00

    A flaw was found in Keycloak. A remote attacker could bypass security controls by sending a valid SAML response from an external Identity Provider (IdP) to the Keycloak SAML endpoint for IdP-initiated broker logins. This allows the attacker to complete broker logins even when…

  • CVE-2025-3501HigApr 29, 2025
    risk 0.46cvss 8.2epss 0.00

    A flaw was found in Keycloak. By setting a verification policy to 'ALL', the trust store certificate verification is skipped, which is unintended.

  • CVE-2021-3461HigApr 1, 2022
    risk 0.46cvss 7.1epss 0.00

    A flaw was found in keycloak where keycloak may fail to logout user session if the logout request comes from external SAML identity provider and Principal Type is set to Attribute [Name].

  • CVE-2024-10039higNov 25, 2024
    risk 0.45cvss epss 0.00

    A vulnerability was found in Keycloak. Deployments of Keycloak with a reverse proxy not using pass-through termination of TLS, with mTLS enabled, are affected. This issue may allow an attacker on the local network to authenticate as any user or client that leverages mTLS as the…

  • CVE-2026-18215MedJul 31, 2026
    risk 0.44cvss 6.8epss 0.00

    Keycloak provides a way to let users log in using Microsoft accounts while restricting access to a specific organization (tenant). A flaw was discovered where this restriction is ignored when using the token exchange feature. This means an attacker with a valid Microsoft token…

  • CVE-2026-18214MedJul 31, 2026
    risk 0.44cvss 6.8epss 0.00

    Keycloak allows users to log in using Google accounts and can be configured to only allow users from specific Google Workspace domains. A flaw was found where the token exchange feature, which allows swapping a Google token for a Keycloak token, does not check these domain…

  • CVE-2021-20262MedMar 9, 2021
    risk 0.44cvss 6.8epss 0.00

    A flaw was found in Keycloak 12.0.0 where re-authentication does not occur while updating the password. This flaw allows an attacker to take over an account if they can obtain temporary, physical access to a user’s browser. The highest threat from this vulnerability is to…

  • CVE-2026-18571MedAug 2, 2026
    risk 0.43cvss 6.6epss 0.00

    A flaw was found in the user creation component of Keycloak when Fine-Grained Admin Permissions V2 (FGAP V2) is enabled. This issue allows a sub-administrator with permission to create users to add those users to any group, even groups the sub-administrator is not authorized to…

  • CVE-2026-18967MedAug 6, 2026
    risk 0.42cvss 6.4epss 0.00

    A flaw was found in the SAML broker component of Keycloak, an identity and access management solution. When configured as a SAML broker using the IdP-Initiated flow, Keycloak fails to enforce the OneTimeUse condition in SAML assertions. This allows an attacker who captures a…

  • CVE-2026-16100MedAug 5, 2026
    risk 0.42cvss 6.5epss 0.00

    A flaw was found in the user-event metrics recording of Keycloak. When metrics are enabled, the system records raw error messages from failed account operations as Prometheus metric labels. Because these error messages can include user-supplied input like nonexistent client IDs,…

  • CVE-2026-18573MedAug 2, 2026
    risk 0.42cvss 6.5epss 0.00

    A flaw was found in the keycloak-services component of Keycloak, which is used for managing authentication and authorization flows. The issue occurs when a realm administrator configures client policies to enforce specific authentication requirements on confidential clients. Due…

  • CVE-2026-18572MedAug 2, 2026
    risk 0.42cvss 6.5epss 0.00

    Keycloak provides authorization services that allow administrators to restrict access to resources based on time policies (for example, only allowing access during business hours). A flaw was discovered where a user can include a fake time value in their authorization request…

  • CVE-2026-18203MedJul 31, 2026
    risk 0.42cvss 6.5epss 0.00

    A flaw was found in the group policy evaluation logic of Keycloak, an identity and access management solution. When a group policy is set to extend permissions to child groups, the system incorrectly uses a simple text-based prefix check to verify group membership. This allows a…

  • CVE-2026-18207MedJul 29, 2026
    risk 0.42cvss 6.5epss 0.00

    A flaw was found in the client policy enforcement mechanism of Keycloak. The issue occurs when the system checks group membership by name instead of a unique identifier. An attacker with client management privileges could bypass security policies by joining a group with a…

  • CVE-2026-17059MedJul 24, 2026
    risk 0.42cvss 6.5epss 0.00

    A flaw was found in the role-users endpoint of the keycloak-services library, which is the core component of the Keycloak identity and access management solution. The issue occurs because the system fails to check if an administrator has permission to view individual users when…

  • CVE-2026-4629MedJun 30, 2026
    risk 0.42cvss 6.5epss 0.00

    A flaw was found in Keycloak. A highly privileged user with `manage-clients` permission can exploit this vulnerability by injecting a hardcoded role mapper into any client. This action allows the user to bypass existing scope restrictions and inject the `realm-admin` role into…

  • CVE-2026-12388MedJun 30, 2026
    risk 0.42cvss 6.5epss 0.00

    A flaw was found in the Identity Provider (IdP) mapper component of Keycloak, which is used to manage how user information from external services is mapped to Keycloak users. An administrator with limited permissions to manage identity providers can exploit this flaw by creating…

  • CVE-2026-7307HigMay 19, 2026
    risk 0.42cvss 7.5epss 0.01

    A flaw was found in Keycloak. A remote, unauthenticated attacker can send a specially crafted XML input to the Security Assertion Markup Language (SAML) endpoint. This malicious input can cause high CPU usage and worker thread starvation, leading to a Denial of Service (DoS)…

  • CVE-2022-2232HigNov 14, 2024
    risk 0.42cvss 7.5epss 0.01

    A flaw was found in the Keycloak package. This flaw allows an attacker to utilize an LDAP injection to bypass the username lookup or potentially perform other malicious actions.

  • CVE-2023-1664MedMay 26, 2023
    risk 0.42cvss 6.5epss 0.00

    A flaw was found in Keycloak. This flaw depends on a non-default configuration "Revalidate Client Certificate" to be enabled and the reverse proxy is not validating the certificate before Keycloak. Using this method an attacker may choose the certificate which will be validated…

  • CVE-2021-3632HigAug 26, 2022
    risk 0.42cvss 7.5epss 0.01

    A flaw was found in Keycloak. This vulnerability allows anyone to register a new security device or key when there is not a device already registered for any user by using the WebAuthn password-less login flow.

  • CVE-2021-20222HigMar 23, 2021
    risk 0.42cvss 7.5epss 0.01

    A flaw was found in keycloak. The new account console in keycloak can allow malicious code to be executed using the referrer URL. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

  • CVE-2020-10758HigSep 16, 2020
    risk 0.42cvss 7.5epss 0.02

    A vulnerability was found in Keycloak before 11.0.1 where DoS attack is possible by sending twenty requests simultaneously to the specified keycloak server, all with a Content-Length header value that exceeds the actual byte count of the request body.

  • CVE-2020-1727MedJun 22, 2020
    risk 0.42cvss 6.4epss 0.01

    A vulnerability was found in Keycloak before 9.0.2, where every Authorization URL that points to an IDP server lacks proper input validation as it allows a wide range of characters. This flaw allows a malicious to craft deep links that introduce further attack scenarios on…

  • CVE-2022-2668HigAug 5, 2022
    risk 0.40cvss 7.2epss 0.01

    An issue was discovered in Keycloak that allows arbitrary Javascript to be uploaded for the SAML protocol mapper even if the UPLOAD_SCRIPTS feature is disabled

  • CVE-2020-1723MedJan 28, 2021
    risk 0.40cvss 6.1epss 0.01

    A flaw was found in Keycloak Gatekeeper (Louketo). The logout endpoint can be abused to redirect logged-in users to arbitrary web pages. Affected versions of Keycloak Gatekeeper (Louketo): 6.0.1, 7.0.0

  • CVE-2020-10748MedSep 16, 2020
    risk 0.40cvss 6.1epss 0.01

    A flaw was found in Keycloak's data filter, in version 10.0.1, where it allowed the processing of data URLs in some circumstances. This flaw allows an attacker to conduct cross-site scripting or further attacks.

Page 1 of 3