CVE-2026-18217: Keycloak-services: keycloak-services: saml http-redirect binding response preserves query string leading to parameter pollution

Published Jul 29, 2026
·
Updated

A flaw was found in the SAML protocol implementation of Keycloak, an open-source identity and access management solution. The issue occurs when Keycloak handles SAML authentication requests using the HTTP-Redirect binding. If a client is configured with a wildcard redirect URL, an attacker can craft a request that includes malicious parameters. When a user authenticates, Keycloak appends its legitimate response to the attacker's parameters. This can cause some service providers to process the attacker's data instead of the real login information, potentially leading to a user being logged into the wrong account.

Other sources

A HTTP Parameter Pollution vulnerability was discovered in Keycloak within the org.keycloak.protocol.saml package. The flaw exists because the SAML HTTP-Redirect binding response preserves the full query string provided in the initial authentication request. An attacker can craft an AuthnRequest with an AssertionConsumerServiceURL that already contains SAMLResponse and RelayState query parameters. If the SAML client is configured with a wildcard redirect URI and allows the attacker to control these parameters, Keycloak will append its own SAML binding parameters to the existing ones in the redirect response. This results in duplicate parameters where the attacker-controlled values appear first. An attacker can exploit this against service providers that only parse the first occurrence of a query parameter to perform login CSRF or session swapping, effectively forcing a victim to authenticate into an attacker-controlled session.

Red Hat

Affected Software

2 affected components
Keycloak Keycloak
redhat Build Of Keycloak

Event History

Jul 29, 2026
Data Sourced
via Red Hat·08:55 AM
DescriptionSeverityAffected Software
Jul 31, 2026
CVE Published
via MITRE·06:38 AM
Data Sourced
via MITRE·06:38 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:16 AM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-18217?

The severity of CVE-2026-18217 is rated as low with a score of 3.4.

2

What does CVE-2026-18217 affect?

CVE-2026-18217 affects the SAML protocol implementation in Keycloak, specifically during HTTP-Redirect binding.

3

How can I fix CVE-2026-18217?

To fix CVE-2026-18217, ensure that the redirect URLs configured in Keycloak do not use wildcards.

4

What type of vulnerability is CVE-2026-18217?

CVE-2026-18217 is categorized under input validation vulnerabilities with a potential for parameter pollution.

5

What is the risk associated with CVE-2026-18217?

CVE-2026-18217 poses a risk of parameter pollution due to improper handling of query strings in SAML HTTP-Redirect bindings.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203