Common Vulnerabilities and Exposures (CVE)

CVE-2024-10492

Sep 21, 2026 05:52:57 UTC

A vulnerability was found in Keycloak. A user with high privileges could read sensitive information from a Vault file that is not within the expected context. This attacker must have previous high access to the Keycloak server in order to p...

CVE-2024-9666

Sep 21, 2026 05:52:49 UTC

A vulnerability was found in the Keycloak Server. The Keycloak Server is vulnerable to a denial of service (DoS) attack due to improper handling of proxy headers. When Keycloak is configured to accept incoming proxy headers, it may accept n...

CVE-2026-15711

Sep 21, 2026 05:49:03 UTC

A vulnerability was found in libsoup's WebSocket frame parsing implementation. The library fails to validate length rules specified in RFC 6455 §5.5, which mandates that all WebSocket control frames (e.g., PING, PONG, CLOSE) contain a paylo...

CVE-2026-15709

Sep 21, 2026 05:49:02 UTC

A flaw was found in libsoup's WebSocket implementation when using the permessage-deflate extension. The extension's decompression loop (inflate()) processes data in chunks without enforcing an upper boundary limit on the output buffer size....

CVE-2026-54231

Sep 21, 2026 05:48:59 UTC

A content injection vulnerability was found in the ABRT post-create event handler scripts in libreport. The event script queries the systemd journal for log entries matching the crashed process and writes the results to files in the dump di...

CVE-2025-11234

Sep 21, 2026 05:47:49 UTC

A flaw was found in QEMU. If the QIOChannelWebsock object is freed while it is waiting to complete a handshake, a GSource is leaked. This can lead to the callback firing later on and triggering a use-after-free in the use of the channel. Th...

CVE-2024-8176

Sep 21, 2026 05:47:06 UTC

A stack overflow vulnerability exists in the libexpat library due to the way it handles recursive entity expansion in XML documents. When parsing an XML document with deeply nested entity references, libexpat can be forced to recurse indefi...

CVE-2025-3910

Sep 21, 2026 05:47:04 UTC

A flaw was found in Keycloak. The org.keycloak.authorization package may be vulnerable to circumventing required actions, allowing users to circumvent requirements such as setting up two-factor authentication.

CVE-2025-2559

Sep 21, 2026 05:47:02 UTC

A flaw was found in Keycloak. When the configuration uses JWT tokens for authentication, the tokens are cached until expiration. If a client uses JWT tokens with an excessively long expiration time, for example, 24 or 48 hours, the cache ca...

CVE-2025-1391

Sep 21, 2026 05:46:57 UTC

A flaw was found in the Keycloak organization feature, which allows the incorrect assignment of an organization to a user if their username or email matches the organization’s domain pattern. This issue occurs at the mapper level, leading t...

CVE-2025-0604

Sep 21, 2026 05:46:56 UTC

A flaw was found in Keycloak. When an Active Directory user resets their password, the system updates it without performing an LDAP bind to validate the new credentials against AD. This vulnerability allows users whose AD accounts are expir...

CVE-2024-10451

Sep 21, 2026 05:46:52 UTC

A flaw was found in Keycloak. This issue occurs because sensitive runtime values, such as passwords, may be captured during the Keycloak build process and embedded as default values in bytecode, leading to unintended information disclosure....

CVE-2024-10270

Sep 21, 2026 05:46:51 UTC

A vulnerability was found in the Keycloak-services package. If untrusted data is passed to the SearchQueryUtils method, it could lead to a denial of service (DoS) scenario by exhausting system resources due to a Regex complexity.

CVE-2026-54230

Sep 21, 2026 05:29:38 UTC

A symlink following vulnerability was found in the ABRT post-create event handler scripts in libreport. Event scripts write output files using shell redirections without the O_NOFOLLOW flag. If the target file is replaced with a symlink, th...

CVE-2026-63622

Sep 21, 2026 05:28:23 UTC

A flaw was found in libvirt. A local attacker, specifically a process running as the confined `swtpm` user, could exploit a symlink-following vulnerability in the `virFileChownFiles()` function. By planting a symbolic link within the `swtpm...