Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

KeyCloak — Vulnerabilities & Security Advisories 89

All 89 CVE vulnerabilities found in KeyCloak, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security vulnerabilities related to KeyCloak, an open-source identity and access management solution developed by Red Hat. It focuses on common weakness types such as authentication bypass, privilege escalation, and information disclosure found within the product’s architecture and implementation. The collection includes publicly disclosed vulnerabilities and security advisories spanning from the product’s initial releases through recent updates, ensuring a comprehensive historical view of its security posture. This dataset is curated to reflect the evolving threat landscape and the vendor’s response to identified risks over time. Visitors can use this resource to track KeyCloak’s security advisories and understand the progression of specific weakness classes affecting the platform. Users may also look up the product’s vulnerability history to assess long-term stability or to contextualize recent findings against past incidents. This aggregation aids developers, security analysts, and system administrators in making informed decisions regarding deployment, patching, and risk mitigation strategies without needing to search multiple disparate sources. By consolidating these details into a single view, the page supports more efficient security auditing and compliance reporting for organizations relying on KeyCloak for identity management. The information presented is derived from official vendor notifications and reputable security databases, ensuring accuracy and reliability for professional security assessments.

Vendor: JBoss

CVE ID Title CVSS Severity Published
CVE-2026-1609 Org.keycloak/keycloak-quarkus-server: keycloak: unauthorized access via jwt authorization grant with disabled users CWE-284 8.1 High 2026-07-16
CVE-2025-12150 Org.keycloak/keycloak-services: webauthn attestation statement verification bypass CWE-347 3.1 Low 2026-02-27
CVE-2025-13467 Org.keycloak.storage.ldap: keycloak: deserialization of untrusted data in ldap user federation CWE-502 5.5 Medium 2025-11-25
CVE-2025-11538 Keycloak-server: debug default bind address CWE-1327 6.8 Medium 2025-11-13
CVE-2025-12390 Org.keycloak.protocol.oidc.endpoints.logoutendpoint: offline session takeover due to reused authentication session id CWE-384 6.0 Medium 2025-10-28
CVE-2025-10939 Org.keycloak/keycloak-quarkus-server: unable to restrict access to the admin console CWE-427 3.7 Low 2025-10-28
CVE-2025-12110 Keycloak: org.keycloak:keycloak-services: user can refresh offline session even after client's offline_access scope was removed CWE-613 5.4 Medium 2025-10-23
CVE-2025-11429 Keycloak-server: too long and not settings compliant session CWE-613 5.4 Medium 2025-10-23
CVE-2025-10044 Keycloak: keycloak error_description injection on error pages CWE-79 4.3 Medium 2025-09-05
CVE-2025-9162 Org.keycloak/keycloak-model-storage-service: variable injection into environment variables CWE-526 4.9 Medium 2025-08-21
CVE-2025-8419 Org.keycloak/keycloak-services: keycloak smtp inject vulnerability CWE-93 5.3 Medium 2025-08-06
CVE-2023-4918 Plaintext storage of user password CWE-256 8.8 High 2023-09-12
CVE-2023-0264 keycloak 授权问题漏洞 8.8 - 2023-08-04
CVE-2022-4361 Red Hat Keycloak 跨站脚本漏洞 CWE-81 10.0 Critical 2023-07-07
CVE-2023-1664 Red Hat Keycloak 信任管理问题漏洞 CWE-295 8.2 - 2023-05-26
CVE-2022-1274 Keycloak 跨站脚本漏洞 CWE-80 5.4 - 2023-03-29
CVE-2022-2237 Keycloak 输入验证错误漏洞 CWE-601 6.1 - 2023-03-27
CVE-2023-0105 Red Hat Keycloak 授权问题漏洞 6.5 - 2023-01-11
CVE-2023-0091 Red Hat Keycloak 安全漏洞 5.5 - 2023-01-11
CVE-2022-3782 Red Hat Keycloak 路径遍历漏洞 9.3 - 2023-01-11
CVE-2022-2256 Red Hat Keycloak 跨站脚本漏洞 CWE-79 3.8 - 2022-09-01
CVE-2022-0225 Red Hat Keycloak 跨站脚本漏洞 CWE-79 5.4 - 2022-08-26
CVE-2021-3632 Red Hat Single Sign-On 授权问题漏洞 CWE-287 8.1 - 2022-08-26
CVE-2021-3754 Red Hat Keycloak 安全漏洞 CWE-20 5.3 - 2022-08-26
CVE-2021-3856 Red Hat Keycloak 路径遍历漏洞 CWE-552 4.3 - 2022-08-26
CVE-2020-35509 Red Hat Keycloak 信任管理问题漏洞 CWE-20 5.9 - 2022-08-23
CVE-2021-3827 Red Hat Keycloak 授权问题漏洞 CWE-287 6.8 - 2022-08-23
CVE-2021-3513 Red Hat Keycloak 安全漏洞 CWE-522 5.3 - 2022-08-22
CVE-2022-2668 Red Hat Keycloak 安全漏洞 7.2 - 2022-08-05
CVE-2022-1245 Red Hat Keycloak 安全漏洞 CWE-862 9.8 - 2022-07-07

All 89 known CVE vulnerabilities affecting KeyCloak with full Chinese analysis, references, and POCs where available.