CVEs we hold for Keycloak
Records whose assigning authority named Keycloak as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-90997Keycloak: Replay protection bypass leads to unauthorized access via database driver semantics mismatchKeycloak
CVE-2026-1609Org.keycloak/keycloak-quarkus-server: keycloak: unauthorized access via jwt authorization grant with disabled usersKeycloak; Red Hat JBoss Enterprise Application Platform 8…
CVE-2025-9162Org.keycloak/keycloak-model-storage-service: variable injection into environment variableskeycloak; Red Hat build of Keycloak 26.0…
CVE-2025-8419Org.keycloak/keycloak-services: keycloak smtp inject vulnerabilitykeycloak; Red Hat build of Keycloak 26.0…
CVE-2025-13467Org.keycloak.storage.ldap: keycloak: deserialization of untrusted data in ldap user federationKeycloak; Red Hat build of Keycloak 26.2…
CVE-2025-12390Org.keycloak.protocol.oidc.endpoints.logoutendpoint: offline session takeover due to reused authentication session idkeycloak; Red Hat build of Keycloak 26.2…
CVE-2025-12150Org.keycloak/keycloak-services: webauthn attestation statement verification bypasskeycloak; Red Hat build of Keycloak 26.2…
CVE-2025-12110Keycloak: org.keycloak:keycloak-services: user can refresh offline session even after client's offline_access scope was…keycloak; Red Hat build of Keycloak 26.2…
CVE-2025-11429Keycloak-server: too long and not settings compliant sessionkeycloak; Red Hat build of Keycloak 26.2…
CVE-2025-10939Org.keycloak/keycloak-quarkus-server: unable to restrict access to the admin consolekeycloak; Red Hat build of Keycloak 26.4…
CVE-2025-10044Keycloak: keycloak error_description injection on error pageskeycloak; Red Hat build of Keycloak 26.0…
54 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.