15 Total advisories
15 Vulnerabilities
0 Malware
Dependency scanning
Check whether org.keycloak:keycloak-quarkus-server is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
MEDIUM 5.9
CVE-2024-10451
Keycloak Build Process Exposes Sensitive Data
MEDIUM 5.0
CVE-2025-11537
Keycloak logs sensitive headers
LOW 3.7
CVE-2025-10939
Keycloak unable to restrict access to the admin console
MEDIUM 6.8
GHSA-7m9g-pmxf-m9m8
Duplicate Advisory: Keycloak allows Binding to an Unrestricted IP Address
MEDIUM 6.5
CVE-2024-11734
Denial of Service in Keycloak Server via Security Headers
MEDIUM 4.9
CVE-2024-11736
Keycloak allows unrestricted admin use of system and environment variables
MEDIUM 4.7
CVE-2024-9666
Keycloak proxy header handling Denial-of-Service (DoS) vulnerability
LOW 2.7
CVE-2024-10492
Keycloak Path Traversal Vulnerability Due to External Control of File Name or Path
LOW 3.7
CVE-2026-0976
Keycloak has an improper input validation vulnerability
LOW 3.7
GHSA-c6cm-5gc7-c3f4
Duplicate Advisory: Keycloak allows access to admin path through flaw
MEDIUM 5.7
CVE-2024-10973
Keycloak on Quarkus CLI option for encrypted JGroups ignored
MEDIUM 5.7
GHSA-6mpx-pmgp-ww49
Duplicate Advisory: Keycloak vulnerable to Cleartext Transmission of Sensitive Information
MEDIUM 5.9
GHSA-jcgg-mg9g-p9wf
Duplicate Advisory: Keycloak Build Process Exposes Sensitive Data
LOW 2.7
GHSA-6vrw-mpj8-3j59
Duplicate Advisory: Keycloak Path Traversal Vulnerability Due to External Control of File Name or Path
MEDIUM 4.7
GHSA-pcx7-8hxg-j823
Duplicate Advisory: Keycloak proxy header handling Denial-of-Service (DoS) vulnerability
Browse more Maven advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes