7 Total advisories
7 Vulnerabilities
0 Malware
Dependency scanning
Check whether org.keycloak:keycloak-server-spi-private is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
MEDIUM 4.3
CVE-2026-9791
Keycloak Vulnerable to Incorrect Authorization
MEDIUM 6.8
CVE-2026-9704
Keycloak Vulnerable to Improper Validation of Specified Quantity in Input
HIGH 8.1
CVE-2026-2603
Keycloak: Unauthorized authentication via disabled SAML Identity Provider
MEDIUM 4.3
CVE-2026-3190
Keycloak: Missing Role Enforcement on UMA 2.0 Permission Ticket Endpoint Leads to Information Disclosure
MEDIUM 4.9
CVE-2026-0871
Keycloak Server Private SPI: Improper Access Control Allows Administrators to Bypass Attribute Visibility Restrictions and Modify Unmanaged User Profile Attributes
MEDIUM 4.8
CVE-2020-10776
Cross-site Scripting in keycloak
LOW 3.5
CVE-2023-2585
Client Spoofing within the Keycloak Device Authorisation Grant
Browse more Maven advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes