Keycloak是Keycloak开源的一种开源身份和访问管理解决方案。 Keycloak存在安全特征问题漏洞,该漏洞源于jwt-authorization-grant流程中服务器未在颁发令牌前验证身份提供商是否启用,可能导致攻击者使用已禁用身份提供商的签名密钥生成有效断言。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat build of Keycloak 26.4 | 26.4.9-1< * |
unaffected |
26.4-11< * |
unaffected | ||
26.4-10< * |
unaffected | ||
| Red Hat | Red Hat build of Keycloak 26.4.9 | any |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat build of Keycloak 26.4 | 26.4.9-1 ~ * |
cpe:/a:redhat:build_keycloak:26.4::el9
|
|
| Red Hat | Red Hat build of Keycloak 26.4 | 26.4-11 ~ * |
cpe:/a:redhat:build_keycloak:26.4::el9
|
|
| Red Hat | Red Hat build of Keycloak 26.4 | 26.4-10 ~ * |
cpe:/a:redhat:build_keycloak:26.4::el9
|
|
| Red Hat | Red Hat build of Keycloak 26.4.9 | - |
cpe:/a:redhat:build_keycloak:26.4::el9
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-1529 | 8.1 HIGH | Org.keycloak.services.resources.organizations: keycloak: unauthorized organization registr |
| CVE-2025-14778 | 5.4 MEDIUM | Keycloak: incorrect ownership checks in /uma-policy/ |
No comments yet