Keycloak是Keycloak开源的一种开源身份和访问管理解决方案。 Keycloak存在安全漏洞,该漏洞源于具有高权限的远程攻击者(如配置恶意LDAP服务器的领域管理员或攻击者破坏上游LDAP服务器)可通过在密码身份验证请求期间发送格式错误的LDAP密码策略响应,触发OutOfMemoryError,可能导致Keycloak Java虚拟机终止,从而导致受影响节点上所有领域的拒绝服务。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat build of Keycloak 26.4 | 26.4.13-1< * |
unaffected |
26.4-19< * |
unaffected | ||
26.4-19< * |
unaffected | ||
| Red Hat | Red Hat build of Keycloak 26.4.13 | any |
unaffected |
| Red Hat | Red Hat build of Keycloak 26.6 | 26.6.3-3< * |
unaffected |
26.6-6< * |
unaffected | ||
26.6-6< * |
unaffected | ||
| Red Hat | Red Hat build of Keycloak 26.6.3 | any |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat build of Keycloak 26.4 | 26.4.13-1 ~ * |
cpe:/a:redhat:build_keycloak:26.4::el9
|
|
| Red Hat | Red Hat build of Keycloak 26.4 | 26.4-19 ~ * |
cpe:/a:redhat:build_keycloak:26.4::el9
|
|
| Red Hat | Red Hat build of Keycloak 26.4 | 26.4-19 ~ * |
cpe:/a:redhat:build_keycloak:26.4::el9
|
|
| Red Hat | Red Hat build of Keycloak 26.4.13 | - |
cpe:/a:redhat:build_keycloak:26.4::el9
|
|
| Red Hat | Red Hat build of Keycloak 26.6 | 26.6.3-3 ~ * |
cpe:/a:redhat:build_keycloak:26.6::el9
|
|
| Red Hat | Red Hat build of Keycloak 26.6 | 26.6-6 ~ * |
cpe:/a:redhat:build_keycloak:26.6::el9
|
|
| Red Hat | Red Hat build of Keycloak 26.6 | 26.6-6 ~ * |
cpe:/a:redhat:build_keycloak:26.6::el9
|
|
| Red Hat | Red Hat build of Keycloak 26.6.3 | - |
cpe:/a:redhat:build_keycloak:26.6::el9
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-4408 | 9.0 CRITICAL | Samba: remote code execution in samr |
| CVE-2026-9804 | 7.7 HIGH | Kubevirt: kubevirt: vmexport directory symlink escape enables exporter pod file read |
| CVE-2026-9795 | 7.3 HIGH | Keycloak: keycloak: privilege escalation via improper scope mapping enforcement |
| CVE-2026-44604 | 7.0 HIGH | Rpm: command injection in rpmuncompress dountar() via unescaped archive top-level director |
| CVE-2026-9802 | 6.8 MEDIUM | Keycloak: keycloak: unauthorized account access via replayed refresh tokens after cluster |
| CVE-2026-9792 | 6.5 MEDIUM | Keycloak: keycloak: security restriction bypass allows unauthorized ropc token acquisition |
| CVE-2026-9796 | 6.5 MEDIUM | Keycloak: keycloak: privilege escalation via time-of-check to time-of-use (toctou) vulnera |
| CVE-2026-9793 | 5.9 MEDIUM | Keycloak: keycloak: security policy bypass in jwe-encrypted request object processing |
| CVE-2026-9794 | 5.3 MEDIUM | Keycloak: keycloak: information disclosure via saml ecp endpoint |
| CVE-2026-9803 | 5.3 MEDIUM | Keycloak: keycloak: denial of service via malformed authorization header |
| CVE-2026-9791 | 4.3 MEDIUM | Keycloak-rhel9: organization data leak after feature disabled in keycloak |
| CVE-2026-9798 | 4.3 MEDIUM | Keycloak: keycloak: brute-force protection bypass in ciba flow |
| CVE-2026-10028 | 4.3 MEDIUM | Glib-networking: infinite loop in glib-networking gnutls backend allows remote denial of s |
No comments yet