Where
-Infinity
0

Keycloak KeycloakKeycloak-services: keycloak-services: saml onetimeuse assertion replay in idp-initiated broker flow

Risk 60
Severity
8.1
First published (updated )

KeycloakKeycloak-services: keycloak-services: client access-type policy condition bypass during client update

Risk 38
Severity
6.5
First published (updated )

Keycloak KeycloakKeycloak-services: keycloak-services: uma claim token can override authorization time-policy evaluation attributes

Risk 38
Severity
6.5
First published (updated )

Keycloak KeycloakKeycloak-services: keycloak-services: fgap v2 group assignment bypass during user creation

Risk 66
Severity
7.2
First published (updated )

keycloak-servicesKeycloak-services: keycloak-services: full-scope-disabled client policy validation bypass via omitted fullscopeallowed

Risk 34
Severity
5.4
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Keycloak keycloak-servicesKeycloak-services: keycloak-services: oidc backchannel logout accepts unsigned forged logout tokens

Risk 20
Severity
3.7
First published (updated )

keycloak-servicesKeycloak-services: keycloak-services: client not-before revocation ignored when realm not-before is older but nonzero

Risk 34
Severity
5.4
First published (updated )

Keycloak KeycloakKeycloak-services: keycloak-services: saml http-redirect binding response preserves query string leading to parameter pollution

Risk 24
Severity
4.7
First published (updated )

Microsoft Keycloak social identity provider in Keycloak (Microsoft external identity provider)Keycloak-services: keycloak-services: microsoft external access-token exchange bypasses configured tenant

Risk 60
Severity
8.1
First published (updated )

Keycloak Keycloak Google Identity Provider (external access-token exchange)Keycloak-services: keycloak-services: google external access-token exchange bypasses hosted-domain restriction

Risk 60
Severity
8.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Keycloak KeycloakKeycloak-services: keycloak-services: client policy source-group condition bypass via duplicate group name matching

Risk 38
Severity
6.5
First published (updated )

Keycloak secure-client-uris (client policy executor)Keycloak-services: keycloak-services: secure-client-uris policy bypass via localhost-prefixed domains

Risk 34
Severity
5.4
First published (updated )

Keycloak keycloak-servicesKeycloak-services: keycloak-services: oidc redirect_uri fragment bypass in http parameter pollution check

Risk 24
Severity
4.7
First published (updated )

Keycloak keycloak-servicesKeycloak-services: keycloak-services: inactive out-of-audience token introspection leaks signed jwt claim

Risk 38
Severity
6.5
First published (updated )

Keycloak KeycloakKeycloak-services: keycloak-services: client policy source-host wildcard domain matching bypass

Risk 20
Severity
3.7
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Keycloak KeycloakKeycloak-services: keycloak-services: group policy extendchildren matches sibling group path prefixes

Risk 38
Severity
6.5
First published (updated )

Keycloak KeycloakKeycloak-services: keycloak-services: generic identity-provider creation can bind brokers to organizations without manage-organizations

Risk 39
Severity
5.5
First published (updated )

Keycloak keycloak-servicesKeycloak-services: keycloak-services: information disclosure via role-users endpoint bypasses per-user view filter

Risk 38
Severity
6.5
First published (updated )

Keycloak Keycloak Admin REST APIKeycloak-services: keycloak-services: vault-resolved rotated client secrets leaked via admin rest api

Risk 39
Severity
5.5
First published (updated )

redhat Build Of KeycloakKeycloak-services: keycloak-services: saml broker metadata import disables response signature validation

Risk 66
Severity
9.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

redhat Build Of KeycloakKeycloak-services: keycloak-services: saml idp-initiated broker login bypasses link-only restriction

Risk 86
Severity
9.8
First published (updated )

Keycloak Keycloak Admin REST APIKeycloak-services: keycloak-services: realm default-group reads disclose hidden groups under fgap v2

Risk 38
Severity
6.5
First published (updated )

Keycloak KeycloakKeycloak-services: keycloak-services: incorrect authorization in admin role-composite deletion allows delegated admin to remove privileged child roles

Risk 30
Severity
4.9
First published (updated )

Keycloak RoleContainerResourceKeycloak-services: keycloak-services: missing per-role authorization on rolecontainerresource composite endpoints

Risk 30
Severity
4.9
First published (updated )

Keycloak keycloak-servicesKeycloak-services: keycloak-services: authenticator config endpoint exposes raw recaptcha secrets to view-only admins

Risk 38
Severity
6.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Keycloak KeycloakKeycloak-services: keycloak-services: incomplete fix for ciba brute-force lockout bypass at token redemption

Risk 22
Severity
4.3
First published (updated )

redhat Build Of KeycloakKeycloak-services: keycloak-services: default dcr policy allows role forgery via user property mappers

Risk 60
Severity
8.1
First published (updated )

Keycloak KeycloakKeycloak-services: keycloak-services: unbounded metric cardinality in user event metrics via request-controlled error text

Risk 38
Severity
6.5
First published (updated )

Keycloak keycloak-servicesKeycloak-services: keycloak-services: required signed-jwt assertion policy can be bypassed with unsigned assertion headers

Risk 34
Severity
5.4
First published (updated )

Red Hat Red Hat Build of Keycloak keycloak-servicesKeycloak-services: keycloak-services: authorization codes can be retargeted to another client session

Risk 41
Severity
5.9
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203