目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

CVE-2026-18211— Keycloak-services localhost前缀域名绕过安全客户端URI策略漏洞

CVSS 4.2 · Medium EPSS 0.19% · P9

Possible ATT&CK Techniques 1AI

T1562.001

Affected Version Matrix 6

ベンダープロダクトVersion Rangeステータス
Red HatRed Hat Build of Keycloakanyaffected
anyaffected
anyaffected
Red HatRed Hat Data Grid 8anyunaffected
Red HatRed Hat JBoss Enterprise Application Platform Expansion Packanyunaffected
Red HatRed Hat Single Sign-On 7anyunaffected
新しい脆弱性情報の通知を購読するログインして購読

I. CVE-2026-18211の基本情報

脆弱性情報

脆弱性についてご質問がありますか?Shenlongの分析が参考になるかご確認ください!
Shenlongの10の質問を表示 ↗

高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。

脆弱性タイトル
Keycloak-services: keycloak-services: secure-client-uris policy bypass via localhost-prefixed domains
ソース: CVE Program / CVE List V5
脆弱性説明
A flaw was found in the secure-client-uris client policy executor within Keycloak core services. This component is responsible for enforcing security requirements on client configurations, such as requiring encrypted connections for redirect URIs. Due to an improper check that only looks at the start of a web address rather than properly verifying the host, an attacker can bypass these security restrictions by using a specially crafted domain name. This could allow an attacker to intercept sensitive authentication codes over unencrypted connections.
ソース: CVE Program / CVE List V5
CVSS情報
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
ソース: CVE Program / CVE List V5
脆弱性タイプ
输入验证不恰当
ソース: CVE Program / CVE List V5

影響を受ける製品

ベンダープロダクト影響を受けるバージョンCPE購読
Red HatRed Hat Build of Keycloak-cpe:/a:redhat:build_keycloak:
Red HatRed Hat Build of Keycloak-cpe:/a:redhat:build_keycloak:
Red HatRed Hat Build of Keycloak-cpe:/a:redhat:build_keycloak:
Red HatRed Hat Data Grid 8-cpe:/a:redhat:jboss_data_grid:8
Red HatRed Hat JBoss Enterprise Application Platform Expansion Pack-cpe:/a:redhat:jbosseapxp
Red HatRed Hat Single Sign-On 7-cpe:/a:redhat:red_hat_single_sign_on:7

II. CVE-2026-18211の公開POC

#POC説明ソースリンクShenlongリンク
AI生成POCプレミアム

公開POCは見つかりませんでした。

ログインしてAI POCを生成

III. CVE-2026-18211のインテリジェンス情報

登录查看更多情报信息。

CVE-2026-18211 厂商安全公告 (1)

CVE-2026-18211 其他参考 (1)

Same Patch Batch · Red Hat · 2026-07-31 · 14 CVEs total

CVE-2026-100798.5 HIGHStackrox: stackrox: deploy-time policy enforcement and visibility bypass via label injecti
CVE-2026-181418.2 HIGHAap-gateway: aap-gateway: authentication bypass in event-driven ansible via forged http he
CVE-2026-157227.5 HIGH389-ds-base: 389-ds-base: pre-authentication stack buffer overflow in get_ruvelement_from_
CVE-2026-117707.5 HIGH389-ds-base: 389-ds-base: pre-auth ldap filter injection in cleanallruv status check
CVE-2026-182156.8 MEDIUMKeycloak-services: keycloak-services: microsoft external access-token exchange bypasses co
CVE-2026-182146.8 MEDIUMKeycloak-services: keycloak-services: google external access-token exchange bypasses hoste
CVE-2026-182086.5 MEDIUMKeycloak-services: keycloak-services: inactive out-of-audience token introspection leaks s
CVE-2026-182036.5 MEDIUMKeycloak-services: keycloak-services: group policy extendchildren matches sibling group pa
CVE-2026-161054.9 MEDIUMKeycloak-services: keycloak-services: missing per-role authorization on rolecontainerresou
CVE-2026-182184.2 MEDIUMKeycloak-services: keycloak-services: client not-before revocation ignored when realm not-
CVE-2026-182063.7 LOWKeycloak-services: keycloak-services: client policy source-host wildcard domain matching b
CVE-2026-182173.4 LOWKeycloak-services: keycloak-services: saml http-redirect binding response preserves query
CVE-2026-182093.4 LOWKeycloak-services: keycloak-services: oidc redirect_uri fragment bypass in http parameter

IV. 関連脆弱性

V. CVE-2026-18211へのコメント

まだコメントはありません


コメントを残す