7 Total advisories
7 Vulnerabilities
0 Malware
Dependency scanning
Check whether org.keycloak:keycloak-ldap-federation is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
MEDIUM 4.9
CVE-2026-9801
Keycloak Vulnerable to Improper Validation of Specified Quantity in Input
MEDIUM 5.5
CVE-2025-13467
Keycloak LDAP User Federation provider enables admin-triggered untrusted Java deserialization
MEDIUM 5.5
GHSA-93vm-mqpw-8wh3
Duplicate Advisory: Keycloak LDAP User Federation provider enables admin-triggered untrusted Java deserialization
LOW 2.7
CVE-2024-5967
Keycloak leaks configured LDAP bind credentials through the Keycloak admin console
MEDIUM 5.4
GHSA-m3hp-8546-5qmr
Duplicate Advisory: Authentication Bypass Due to Missing LDAP Bind After Password Reset in Keycloak
MEDIUM 5.4
CVE-2025-0604
Authentication Bypass Due to Missing LDAP Bind After Password Reset in Keycloak
UNKNOWN
CVE-2022-2232
Keycloak vulnerable to LDAP Injection on UsernameForm Login
Browse more Maven advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes