Dependency scanning
Check whether org.keycloak:keycloak-services is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
CVE-2026-2092
Duplicate Advisory: Keycloak: Unauthorized access via improper validation of encrypted SAML assertions
CVE-2026-2092
Keycloak: Unauthorized access via improper validation of encrypted SAML assertions
CVE-2026-9803
Keycloak has an Out-of-bounds Read
CVE-2026-9802
Keycloak has Insufficient Session Expiration
CVE-2026-9798
Keycloak has an Authentication Bypass by Primary Weakness
CVE-2026-9791
Keycloak Vulnerable to Incorrect Authorization
CVE-2026-9795
Keycloak has privilege escalation via improper scope mapping enforcement
CVE-2026-9792
Keycloak Vulnerable to Improper Handling of Insufficient Permissions or Privilege
CVE-2026-9794
Keycloak Generates an Error Message Containing Sensitive Information
GHSA-8hcx-p7m8-gc28
Duplicate Advisory: Keycloak has privilege escalation via improper scope mapping enforcement
CVE-2026-9793
Keycloak has an Improper Verification of Cryptographic Signature issue
CVE-2026-9704
Keycloak Vulnerable to Improper Validation of Specified Quantity in Input
CVE-2026-9689
Keycloak Services has Improper Validation of Consistency within Input
CVE-2026-37981
Keycloak Account Resources user lookup contains broken access control
CVE-2026-4630
Keycloak Protection API allows authenticated clients to access and modify resources owned by other Resource Servers
CVE-2026-8830
Keycloak: Policy bypass during WebAuthn credential registration via client-side JavaScript manipulation
CVE-2026-9087
Keycloak: Insufficient verification proof scoping enables identity provider account linking attack and account compromise
CVE-2026-8922
Keycloak: Revoked Tokens Can Remain Active When Both Realm-Level and Client-Level `notBefore` Revocation Policies are Configured
CVE-2026-7500
Keycloak has a Forced Browsing issue
CVE-2026-4633
Keycloak's identity-first login flow exposes user information
CVE-2026-7504
Keycloak: Open redirect when using wildcard valid redirect URIs in Keycloak
CVE-2026-37982
Keycloak: Unauthorized account takeover via WebAuthn token replay
CVE-2026-37979
Keycloak: Information disclosure via OIDC token introspection endpoint audience bypass
CVE-2026-37978
Keycloak: Information Disclosure via evaluate-scopes Admin API
CVE-2026-7571
Keycloak: Access token disclosure and implicit flow bypass via forged client data
CVE-2026-7507
Keycloak: Session fixation in OIDC login flow that can lead to account takeover
CVE-2026-2603
Keycloak: Unauthorized authentication via disabled SAML Identity Provider
CVE-2026-37980
Keycloak: Arbitrary code execution via Stored Cross-Site Scripting (XSS) in organization selection login page
CVE-2026-4628
Keycloak has Improper Access Control that allows attackers with valid credentials to bypass the allowRemoteResourceManagement=false
CVE-2026-4874
Keycloak Server-Side Request Forgery via OIDC token endpoint manipulation
CVE-2026-37977
Keycloak vulnerable to information disclosure via CORS header injection due to unvalidated JWT azp claim
CVE-2026-3121
Keycloak: manage-clients permission escalates to full realm admin access
CVE-2026-3872
Keycloak: Redirect URI validation bypass via ..;/ path traversal in OIDC auth endpoint
CVE-2026-4325
Keycloak: Replay of action tokens via improper handling of single-use entries
CVE-2026-4282
Keycloak: Privilege escalation via forged authorization codes due to SingleUseObjectProvider isolation flaw
CVE-2026-4636
Keycloak: UMA Policy Resource Injection Allows Unauthorized Cross-User Permission Grants
CVE-2026-4634
Keycloak: Application-Level DoS via Scope Processing
CVE-2026-3190
Keycloak: Missing Role Enforcement on UMA 2.0 Permission Ticket Endpoint Leads to Information Disclosure
CVE-2025-14083
Keycloak Admin REST API exposes backend schema and rules
CVE-2025-14082
Keycloak Admin REST (Representational State Transfer) API does not properly enforce permissions
CVE-2026-3911
Keycloak: Information disclosure of disabled user attributes via administrative endpoint
CVE-2026-3429
Keycloak: Improper Access Control Leading to MFA Deletion and Account Takeover in Keycloak Account REST API
CVE-2026-1035
Keycloak does not validate and update refresh token usage atomically
CVE-2026-2575
Keycloak: Denial of Service due to excessive SAMLRequest decompression
CVE-2021-4133
Improper Authorization in Keycloak
CVE-2022-1274
HTML Injection in Keycloak Admin REST API
CVE-2022-1245
Keycloak vulnerable to privilege escalation on Token Exchange feature
CVE-2026-3009
Keycloak allows authentication using an Identity Provider (IdP) even after it has been disabled by an administrator
CVE-2026-2733
Keycloak: Missing Check on Disabled Client for Docker Registry Protocol
CVE-2026-1190
Keycloak's missing timestamp validation allows attackers to extend SAML response validity periods
CVE-2025-12150
Keycloak REST Services has a WebAuthn Attestation Statement Verification Bypass
CVE-2025-11429
Keycloak does not invalidate sessions when "Remember Me" is disabled
CVE-2025-12110
Keycloak does not invalidate offline sessions when the offline_access scope is removed
CVE-2025-14778
Keycloak Affected by Broken Access Control Vulnerability in the UserManagedPermissionService
CVE-2026-1486
Keycloak fails to verify if an Identity Provider (IdP) is enabled before issuing tokens
CVE-2025-13881
Keycloak Admin API allows an administrator with limited privileges to retrieve sensitive custom attributes
CVE-2026-1529
Keycloak affected by improper invitation token validation
CVE-2025-14559
Keycloak services allows the issuance of access and refresh tokens for disabled users
CVE-2023-6717
Keycloak Cross-site Scripting (XSS) via assertion consumer service URL in SAML POST-binding flow
CVE-2024-8883
Keycloak has Vulnerable Redirect URI Validation Results in Open Redirect
CVE-2024-10270
org.keycloak:keycloak-services has Inefficient Regular Expression Complexity
CVE-2024-4540
Keycloak exposes sensitive information in Pushed Authorization Requests (PAR)
CVE-2023-0264
Keycloak vulnerable to user impersonation via stolen UUID code
CVE-2025-3501
Keycloak hostname verification
CVE-2023-0657
Keycloak vulnerable to impersonation via logout token exchange
CVE-2024-3656
Keycloak's admin API allows low privilege users to use administrative functions
CVE-2024-1249
Keycloak's unvalidated cross-origin messages in checkLoginIframe leads to DDoS
CVE-2023-6544
Keycloak Authorization Bypass vulnerability
CVE-2024-1132
Keycloak path traversal vulnerability in redirection validation
CVE-2023-6787
Keycloak vulnerable to session hijacking via re-authentication
CVE-2023-3597
Keycloak secondary factor bypass in step-up authentication
CVE-2025-12390
Keycloak vulnerable to session takeovers due to reuse of session identifiers
CVE-2025-3910
Keycloak vulnerable to two factor authentication bypass
CVE-2024-2419
Keycloak path traversal vulnerability in the redirect validation
CVE-2024-7341
Keycloak has session fixation in Elytron SAML adapters
CVE-2025-8419
Keycloak SMTP Inject Vulnerability
GHSA-qj5r-2r5p-phc7
Duplicate Advisory: Keycloak-services SMTP Inject Vulnerability
CVE-2025-7365
Keycloak phishing attack via email verification step in first login flow
GHSA-gj52-35xm-gxjh
Duplicate Advisory: Keycloak phishing attack via email verification step in first login flow
CVE-2025-7784
Keycloak Privilege Escalation Vulnerability in Admin Console (FGAPv2 Enabled)
GHSA-83j7-mhw9-388w
Duplicate Advisory: Keycloak Privilege Escalation Vulnerability in Admin Console (FGAPv2 Enabled)
GHSA-r934-w73g-v4p8
Duplicate Advisory: Keycloak hostname verification
GHSA-fx44-2wx5-5fvp
Duplicate Advisory: Keycloak vulnerable to two factor authentication bypass
CVE-2025-2559
Keycloak Denial of Service (DoS) Vulnerability via JWT Token Cache
GHSA-rq4w-cjrr-h8w8
Duplicate Advisory: Keycloak allows Incorrect Assignment of an Organization to a User
CVE-2025-1391
Improper Authorization in Keycloak Organization Mapper Allows Unauthorized Organization Claims
CVE-2024-1722
Keycloak Denial of Service via account lockout
GHSA-vvf8-2h68-9475
Duplicate Advisory: Keycloak Open Redirect vulnerability
CVE-2021-3754
Keycloak's improper input validation allows using email as username
GHSA-j76j-rqwj-jmvv
Duplicate Advisory: Keycloak Session Fixation vulnerability
GHSA-8wm9-24qg-m5qj
Duplicate Advisory: Keycloak has a brute force login protection bypass
GHSA-5968-qw33-h47j
Duplicate Advisory: Keycloak vulnerable to reflected XSS via wildcard in OIDC redirect_uri
GHSA-j3x3-r585-4qhg
Duplicate Advisory: org.keycloak:keycloak-services has Inefficient Regular Expression Complexity
CVE-2022-2232
Keycloak vulnerable to LDAP Injection on UsernameForm Login
GHSA-4vrx-8phj-x3mg
Duplicate Advisory: Keycloak exposes sensitive information in Pushed Authorization Requests (PAR)
GHSA-mwm4-5qwr-g9pf
Keycloak is vulnerable to IDN homograph attack
CVE-2024-4629
Keycloak Services has a potential bypass of brute force protection
CVE-2023-6484
Keycloak vulnerable to log Injection during WebAuthn authentication or registration
CVE-2020-10776
Cross-site Scripting in keycloak
CVE-2014-3652
JBoss KeyCloak Open Redirect
Browse more Maven advisories
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes