Keycloak Keycloak是Keycloak组织开源的一款身份认证与权限管理软件。 Keycloak存在加密问题漏洞,该漏洞源于keycloak-services组件的backchannel注销端点存在缺陷,当OIDC身份提供程序配置为跳过签名验证时,系统错误接受无加密签名的注销请求,可能导致攻击者强制用户注销,干扰其工作。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat Build of Keycloak | any |
affected |
any |
affected | ||
any |
affected | ||
| Red Hat | Red Hat Data Grid 8 | any |
unaffected |
| Red Hat | Red Hat JBoss Enterprise Application Platform Expansion Pack | any |
unaffected |
| Red Hat | Red Hat Single Sign-On 7 | any |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Build of Keycloak | - |
cpe:/a:redhat:build_keycloak:
|
|
| Red Hat | Red Hat Build of Keycloak | - |
cpe:/a:redhat:build_keycloak:
|
|
| Red Hat | Red Hat Build of Keycloak | - |
cpe:/a:redhat:build_keycloak:
|
|
| Red Hat | Red Hat Data Grid 8 | - |
cpe:/a:redhat:jboss_data_grid:8
|
|
| Red Hat | Red Hat JBoss Enterprise Application Platform Expansion Pack | - |
cpe:/a:redhat:jbosseapxp
|
|
| Red Hat | Red Hat Single Sign-On 7 | - |
cpe:/a:redhat:red_hat_single_sign_on:7
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-42169 | 7.3 HIGH | Gimp: gimp apng loader heap-buffer-overflow when fctl width exceeds ihdr width (file-png.c |
| CVE-2026-68743 | 5.5 MEDIUM | Sssd: sssd: pam responder out-of-bounds read via unchecked auth_token_length in protocol v |
| CVE-2026-18103 | 4.9 MEDIUM | Dhcp-server: dhcp-server: persistent denial of service due to buffer overflow via omapi |
| CVE-2026-17614 | 4.4 MEDIUM | Wildfly-core: path traversal on wildfly domain controller |
| CVE-2026-68744 | 3.3 LOW | Sssd: sssd: nss responder uninitialized heap disclosure in initgroups reply |
No comments yet