Common Vulnerabilities and Exposures (CVE)

CVE-2026-8922

Jun 10, 2026 21:22:18 UTC

A flaw was found in Keycloak. When both realm-level and client-level `notBefore` revocation policies are configured, Keycloak's OpenID Connect (OIDC) Introspection feature fails to properly honor the realm-level policy. This allows tokens t...

CVE-2026-8830

Jun 10, 2026 21:22:14 UTC

A flaw was found in Keycloak. An authenticated user can bypass configured WebAuthn policies during credential registration by manipulating client-side JavaScript. This occurs because the server-side processAction() fails to validate that th...

CVE-2026-7500

Jun 10, 2026 21:22:13 UTC

When Keycloak is started with `--features-disabled=account,account-api`, the Account REST API is only partially disabled. Five endpoints under the versioned path `/account/v1alpha1` remain fully functional — including both read and write op...

CVE-2026-9803

Jun 10, 2026 21:22:09 UTC

A flaw was found in Keycloak's ClientRegistrationAuth component. A remote unauthenticated attacker can exploit this vulnerability by sending a specially crafted POST request with a malformed 'Authorization: Bearer' header to any client regi...

CVE-2026-9802

Jun 10, 2026 21:22:06 UTC

A flaw was found in Keycloak. When revokeRefreshToken=true is enabled and persistent session storage is in use, a server restart can reset internal timing mechanisms. This allows a remote attacker, who has previously captured a user's refre...

CVE-2026-9801

Jun 10, 2026 21:22:04 UTC

A flaw was found in Keycloak. A remote attacker with high privileges, such as a realm administrator configuring a malicious Lightweight Directory Access Protocol (LDAP) server or an attacker compromising an upstream LDAP server, could explo...

CVE-2026-9794

Jun 10, 2026 21:22:01 UTC

A flaw was found in Keycloak. A remote, unauthenticated attacker can exploit this vulnerability by sending specially crafted SOAP requests to the SAML ECP (Security Assertion Markup Language Enhanced Client or Proxy) endpoint with varying c...

CVE-2026-9792

Jun 10, 2026 21:21:59 UTC

A flaw was found in Keycloak's Client Policies, specifically within the `org.keycloak.protocol.oidc` component. When certain condition providers (client-type, client-roles, client-attributes, client-scopes) are used to enforce security rest...

CVE-2026-9791

Jun 10, 2026 21:21:55 UTC

A flaw was found in Keycloak. An authenticated user with existing organization membership can exploit this flaw by accessing user-facing APIs, such as the account API or by requesting an OpenID Connect (OIDC) token with the 'organization' s...

CVE-2026-9704

Jun 10, 2026 21:21:53 UTC

A flaw was found in Keycloak. An authenticated user with low privileges can exploit this vulnerability by sending an oversized subject_token JSON Web Token (JWT) to the TokenEndpoint. When the token exceeds a 4000-character limit, it is sil...

CVE-2026-9087

Jun 10, 2026 21:21:53 UTC

A flaw was found in Keycloak. The cross-session verification proof is keyed only by (local userId, idpAlias) and is not bound to the upstream identity that was actually verified, so a second upstream account on the same IdP can consume it a...

CVE-2026-28369

Jun 10, 2026 21:05:10 UTC

A flaw was found in Undertow. When Undertow receives an HTTP request where the first header line starts with one or more spaces, it incorrectly processes the request by stripping these leading spaces. This behavior, which violates HTTP stan...

CVE-2026-28368

Jun 10, 2026 21:05:04 UTC

A flaw was found in Undertow. This vulnerability allows a remote attacker to construct specially crafted requests where header names are parsed differently by Undertow compared to upstream proxies. This discrepancy in header interpretation ...

CVE-2026-28367

Jun 10, 2026 21:04:52 UTC

A flaw was found in Undertow. A remote attacker can exploit this vulnerability by sending `\r\r\r` as a header block terminator. This can be used for request smuggling with certain proxy servers, such as older versions of Apache Traffic Ser...

CVE-2026-45602

Jun 10, 2026 20:09:12 UTC

No cwe for this issue in Windows DHCP Server allows an unauthorized attacker to perform tampering over a network.