Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Keystone — Vulnerabilities & Security Advisories 19

All 19 CVE vulnerabilities found in Keystone, with AI-generated Chinese analysis, references, and POCs.

This page catalogs Common Weakness Enumerations (CWE) associated with the Keystone software product developed by Red Hat. It aggregates security vulnerabilities identified within the Keystone open-source identity service framework, covering historical data up to the present date. Users can track Red Hat’s security advisories regarding Keystone, understand the characteristics and impact of specific weakness classes affecting identity management systems, and look up a product’s vulnerability history to assess long-term security trends. The collection includes details on exploitability, attack vectors, and remediation status to support comprehensive risk assessment and patch management workflows. By centralizing this information, the resource facilitates efficient identification of exposure points and aids security professionals in prioritizing mitigation efforts. Data is sourced from vendor disclosures, public databases, and automated scanning results to ensure accuracy and timeliness. Readers are encouraged to review the accompanying metrics to gauge the frequency and severity of reported issues over time. This aggregated view provides a holistic perspective on the security posture of Keystone, enabling informed decision-making for system administrators and security analysts alike. The page is continuously updated as new vulnerabilities are discovered or existing ones are patched, ensuring that the information remains relevant and actionable for stakeholders responsible for maintaining the integrity of their identity infrastructure.

Vendor: keystone

CVE ID Title CVSS Severity Published
CVE-2026-63421 Keystone: `graphql.maxTake` bypass with negative `take` CWE-20 7.5 High 2026-08-21
CVE-2026-10802 keystonejs keystone GraphQL API Endpoint output-field.ts resource consumption CWE-400 4.3 Medium 2026-06-04
CVE-2026-44394 OpenStack Keystone 安全漏洞 CWE-863 6.0 Medium 2026-05-28
CVE-2026-43000 OpenStack Keystone 安全漏洞 CWE-863 6.0 Medium 2026-05-28
CVE-2026-42999 OpenStack Keystone 安全漏洞 CWE-863 6.0 Medium 2026-05-28
CVE-2026-42998 OpenStack Keystone 安全漏洞 CWE-863 6.0 Medium 2026-05-28
CVE-2026-43001 OpenStack Keystone 安全漏洞 CWE-863 7.9 High 2026-05-01
CVE-2026-40683 OpenStack Keystone 安全漏洞 CWE-843 7.7 High 2026-04-14
CVE-2026-33551 OpenStack Keystone 安全漏洞 CWE-863 3.5 Low 2026-04-10
CVE-2026-33326 @keystone-6/core: `isFilterable` bypass via `cursor` parameter in findMany CWE-863 4.3 Medium 2026-03-24
CVE-2025-65073 Keystone 安全漏洞 CWE-863 7.5 High 2025-11-17
CVE-2025-46720 Keystone has an unintended `isFilterable` bypass that can be used as an oracle to match hidden fields CWE-203 3.1 Low 2025-05-05
CVE-2023-40027 Conditionally missing authorization in @keystone-6/core CWE-862 3.7 Low 2023-08-15
CVE-2023-34247 @keystone-6/auth Open Redirect vulnerability CWE-601 6.1 Medium 2023-06-13
CVE-2022-39382 NODE_ENV in Keystone defaults to development with esbuild CWE-74 9.8 Critical 2022-11-03
CVE-2022-39322 @keystone-6/core vulnerable to field-level access-control bypass for multiselect field CWE-285 9.1 Critical 2022-10-25
CVE-2021-3563 Red Hat OpenStack Platform 安全漏洞 CWE-863 7.4 - 2022-08-26
CVE-2012-1572 OpenStack Keystone 资源管理错误漏洞 7.5 - 2019-11-12
CVE-2013-2255 OpenStack Keystone和OpenStack Compute 信任管理问题漏洞 5.9 - 2019-11-01

All 19 known CVE vulnerabilities affecting Keystone with full Chinese analysis, references, and POCs where available.