REDHAT-BUG-2508311: CSRF

Published Jul 29, 2026
·
Updated

A HTTP Parameter Pollution vulnerability was discovered in Keycloak within the org.keycloak.protocol.saml package. The flaw exists because the SAML HTTP-Redirect binding response preserves the full query string provided in the initial authentication request. An attacker can craft an AuthnRequest with an AssertionConsumerServiceURL that already contains SAMLResponse and RelayState query parameters. If the SAML client is configured with a wildcard redirect URI and allows the attacker to control these parameters, Keycloak will append its own SAML binding parameters to the existing ones in the redirect response. This results in duplicate parameters where the attacker-controlled values appear first. An attacker can exploit this against service providers that only parse the first occurrence of a query parameter to perform login CSRF or session swapping, effectively forcing a victim to authenticate into an attacker-controlled session.

Affected Software

1 affected component
Keycloak org.keycloak.protocol.saml

Event History

Jul 29, 2026
Data Sourced
via Red Hat·08:55 AM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

What is the severity of REDHAT-BUG-2508311?

The severity of REDHAT-BUG-2508311 is classified as medium, rated at 4.

2

What vulnerability type is REDHAT-BUG-2508311?

REDHAT-BUG-2508311 is classified as a HTTP Parameter Pollution vulnerability.

3

How does the REDHAT-BUG-2508311 vulnerability occur?

The REDHAT-BUG-2508311 vulnerability occurs due to the SAML HTTP-Redirect binding response preserving the full query string from the initial authentication request.

4

Who is affected by the REDHAT-BUG-2508311 vulnerability?

The REDHAT-BUG-2508311 vulnerability affects users of Keycloak, specifically within the org.keycloak.protocol.saml package.

5

What is a potential impact of REDHAT-BUG-2508311?

An attacker can exploit REDHAT-BUG-2508311 by crafting an AuthnRequest that could lead to session hijacking or unauthorized accesses.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203