CVE-2026-7307: Keycloak: keycloak: denial of service via specially crafted saml input
A flaw was found in Keycloak. A remote, unauthenticated attacker can send a specially crafted XML input to the Security Assertion Markup Language (SAML) endpoint. This malicious input can cause high CPU usage and worker thread starvation, leading to a Denial of Service (DoS) where the server becomes unavailable.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7307?
CVE-2026-7307 is classified as a medium severity vulnerability due to its potential impact on system performance.
How do I fix CVE-2026-7307?
To fix CVE-2026-7307, update Keycloak to the latest version that addresses the denial of service vulnerability.
Who can exploit CVE-2026-7307?
CVE-2026-7307 can be exploited by a remote, unauthenticated attacker who sends specially crafted XML input.
What type of attack is CVE-2026-7307 associated with?
CVE-2026-7307 is associated with a denial of service attack, causing high CPU usage.
Which software versions are affected by CVE-2026-7307?
CVE-2026-7307 affects all versions of Keycloak prior to the security fix.