REDHAT-BUG-2508305: Low severity Red Hat Keycloak vulnerability

Published Jul 29, 2026
·
Updated

An incomplete fix for CVE-2026-9689 was identified in Keycloak's RedirectUtils.containsForbiddenOidcParameters() method. While the original fix successfully blocks forbidden OIDC parameters (such as code, state, and iss) in the URI query string, it fails to inspect the URI fragment (#). When a client is configured with a wildcard redirect URI, an attacker can supply a redirecturi containing these forbidden parameters within the fragment. Because matchesRedirects strips fragments during prefix matching, the crafted URI is accepted. During the authorization response, Keycloak appends its own parameters to the attacker-supplied fragment, leading to a polluted response where attacker-controlled values appear first. Exploitation Conditions: The target client must have a wildcard-registered redirect URI (e.g., https://app.example.com/).

The attacker must induce a victim to follow a crafted authorization URL.

The relying party (client application) must use a first-wins parsing strategy for duplicate parameters.

Concrete Impact: Injection of attacker-controlled iss (issuer), state, and accesstoken parameters.

Potential for session fixation or account confusion if the relying party does not validate parameters per RFC 9207.

Affected Software

1 affected component
Red Hat Keycloak

Event History

Jul 29, 2026
Data Sourced
via Red Hat·08:20 AM
DescriptionSeverityAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of REDHAT-BUG-2508305?

The severity of REDHAT-BUG-2508305 is rated as low.

2

How do I fix REDHAT-BUG-2508305?

To fix REDHAT-BUG-2508305, ensure you apply the latest updates or patches provided by Red Hat for Keycloak.

3

What issue does REDHAT-BUG-2508305 address?

REDHAT-BUG-2508305 addresses an incomplete fix for CVE-2026-9689 related to the handling of forbidden OIDC parameters in Keycloak.

4

Is the vulnerability in REDHAT-BUG-2508305 critical?

No, the vulnerability in REDHAT-BUG-2508305 is classified as low severity.

5

What software is affected by REDHAT-BUG-2508305?

Red Hat Keycloak is the software affected by REDHAT-BUG-2508305.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203