REDHAT-BUG-2479586: Medium severity Red Hat Keycloak vulnerability
Published May 18, 2026
·Updated
OIDC Introspection fails to honor realm-level notBefore revocation policies when a client-level notBefore value is also present, allowing revoked tokens to remain active.
Affected Software
1 affected component
Red Hat Keycloak
Event History
May 18, 2026
Data Sourced
via Red Hat·02:51 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2479586?
The severity of REDHAT-BUG-2479586 is medium with a score of 4.
2
What is the main issue described in REDHAT-BUG-2479586?
REDHAT-BUG-2479586 describes a failure in OIDC Introspection to honor realm-level notBefore revocation policies when a client-level notBefore value is also present.
3
How does REDHAT-BUG-2479586 affect token revocation?
This vulnerability allows revoked tokens to remain active due to the failure in enforcing notBefore revocation at the realm level.
4
Which software is impacted by REDHAT-BUG-2479586?
REDHAT-BUG-2479586 impacts Red Hat Keycloak.
5
How can organizations mitigate the risks associated with REDHAT-BUG-2479586?
Organizations should review their Keycloak configurations to ensure they comply with correct revocation policies and apply any available patches as soon as they're released.