Vulnerabilities
CVE-2026-9087
Keycloak: Insufficient verification proof scoping enables identity provider account linking attack and account compromise
CVE-2026-8922
Keycloak: Revoked Tokens Can Remain Active When Both Realm-Level and Client-Level `notBefore` Revocation Policies are Configured
CVE-2026-8830
Keycloak: Policy bypass during WebAuthn credential registration via client-side JavaScript manipulation
CVE-2026-7500
Keycloak has a Forced Browsing issue
CVE-2026-7504
Keycloak: Open redirect when using wildcard valid redirect URIs in Keycloak
CVE-2026-37982
Keycloak: Unauthorized account takeover via WebAuthn token replay
CVE-2026-37979
Keycloak: Information disclosure via OIDC token introspection endpoint audience bypass
CVE-2026-37978
Keycloak: Information Disclosure via evaluate-scopes Admin API
CVE-2026-7571
Keycloak: Access token disclosure and implicit flow bypass via forged client data
CVE-2026-7507
Keycloak: Session fixation in OIDC login flow that can lead to account takeover
CVE-2026-2603
Keycloak: Unauthorized authentication via disabled SAML Identity Provider
CVE-2026-37980
Keycloak: Arbitrary code execution via Stored Cross-Site Scripting (XSS) in organization selection login page
CVE-2026-4628
Keycloak has Improper Access Control that allows attackers with valid credentials to bypass the allowRemoteResourceManagement=false
CVE-2026-4874
Keycloak Server-Side Request Forgery via OIDC token endpoint manipulation
CVE-2026-4633
Keycloak's identity-first login flow exposes user information
CVE-2026-2092
Keycloak: Unauthorized access via improper validation of encrypted SAML assertions
CVE-2026-37977
Keycloak vulnerable to information disclosure via CORS header injection due to unvalidated JWT azp claim
CVE-2026-3121
Keycloak: manage-clients permission escalates to full realm admin access
CVE-2026-3872
Keycloak: Redirect URI validation bypass via ..;/ path traversal in OIDC auth endpoint
CVE-2026-4325
Keycloak: Replay of action tokens via improper handling of single-use entries
CVE-2026-4282
Keycloak: Privilege escalation via forged authorization codes due to SingleUseObjectProvider isolation flaw
CVE-2026-4636
Keycloak: UMA Policy Resource Injection Allows Unauthorized Cross-User Permission Grants
CVE-2026-4634
Keycloak: Application-Level DoS via Scope Processing
CVE-2026-3190
Keycloak: Missing Role Enforcement on UMA 2.0 Permission Ticket Endpoint Leads to Information Disclosure
CVE-2025-14083
Keycloak Admin REST API exposes backend schema and rules
CVE-2025-14082
Keycloak Admin REST (Representational State Transfer) API does not properly enforce permissions
CVE-2026-3911
Keycloak: Information disclosure of disabled user attributes via administrative endpoint
CVE-2026-3429
Keycloak: Improper Access Control Leading to MFA Deletion and Account Takeover in Keycloak Account REST API
CVE-2026-1035
Keycloak does not validate and update refresh token usage atomically
CVE-2026-2575
Keycloak: Denial of Service due to excessive SAMLRequest decompression
CVE-2021-4133
Improper Authorization in Keycloak
CVE-2022-1274
HTML Injection in Keycloak Admin REST API
CVE-2022-1245
Keycloak vulnerable to privilege escalation on Token Exchange feature
CVE-2026-3009
Keycloak allows authentication using an Identity Provider (IdP) even after it has been disabled by an administrator
CVE-2026-2733
Keycloak: Missing Check on Disabled Client for Docker Registry Protocol
CVE-2026-1190
Keycloak's missing timestamp validation allows attackers to extend SAML response validity periods
CVE-2025-12150
Keycloak REST Services has a WebAuthn Attestation Statement Verification Bypass
CVE-2025-11429
Keycloak does not invalidate sessions when "Remember Me" is disabled
CVE-2025-12110
Keycloak does not invalidate offline sessions when the offline_access scope is removed
CVE-2025-14778
Keycloak Affected by Broken Access Control Vulnerability in the UserManagedPermissionService
CVE-2026-1486
Keycloak fails to verify if an Identity Provider (IdP) is enabled before issuing tokens
CVE-2025-13881
Keycloak Admin API allows an administrator with limited privileges to retrieve sensitive custom attributes
CVE-2026-1529
Keycloak affected by improper invitation token validation
CVE-2025-14559
Keycloak services allows the issuance of access and refresh tokens for disabled users
CVE-2023-6717
Keycloak Cross-site Scripting (XSS) via assertion consumer service URL in SAML POST-binding flow
CVE-2024-8883
Keycloak has Vulnerable Redirect URI Validation Results in Open Redirect
CVE-2024-10270
org.keycloak:keycloak-services has Inefficient Regular Expression Complexity
CVE-2024-4540
Keycloak exposes sensitive information in Pushed Authorization Requests (PAR)
CVE-2023-0264
Keycloak vulnerable to user impersonation via stolen UUID code
CVE-2025-3501
Keycloak hostname verification
CVE-2023-0657
Keycloak vulnerable to impersonation via logout token exchange
CVE-2024-3656
Keycloak's admin API allows low privilege users to use administrative functions
CVE-2024-1249
Keycloak's unvalidated cross-origin messages in checkLoginIframe leads to DDoS
CVE-2023-6544
Keycloak Authorization Bypass vulnerability
CVE-2024-1132
Keycloak path traversal vulnerability in redirection validation
CVE-2023-6787
Keycloak vulnerable to session hijacking via re-authentication
CVE-2023-3597
Keycloak secondary factor bypass in step-up authentication
CVE-2025-12390
Keycloak vulnerable to session takeovers due to reuse of session identifiers
CVE-2025-3910
Keycloak vulnerable to two factor authentication bypass
CVE-2024-2419
Keycloak path traversal vulnerability in the redirect validation
CVE-2024-7341
Keycloak has session fixation in Elytron SAML adapters
CVE-2025-8419
Keycloak SMTP Inject Vulnerability
GHSA-qj5r-2r5p-phc7
Duplicate Advisory: Keycloak-services SMTP Inject Vulnerability
CVE-2025-7365
Keycloak phishing attack via email verification step in first login flow
GHSA-gj52-35xm-gxjh
Duplicate Advisory: Keycloak phishing attack via email verification step in first login flow
CVE-2025-7784
Keycloak Privilege Escalation Vulnerability in Admin Console (FGAPv2 Enabled)
GHSA-83j7-mhw9-388w
Duplicate Advisory: Keycloak Privilege Escalation Vulnerability in Admin Console (FGAPv2 Enabled)
GHSA-r934-w73g-v4p8
Duplicate Advisory: Keycloak hostname verification
GHSA-fx44-2wx5-5fvp
Duplicate Advisory: Keycloak vulnerable to two factor authentication bypass
CVE-2025-2559
Keycloak Denial of Service (DoS) Vulnerability via JWT Token Cache
GHSA-rq4w-cjrr-h8w8
Duplicate Advisory: Keycloak allows Incorrect Assignment of an Organization to a User
CVE-2025-1391
Improper Authorization in Keycloak Organization Mapper Allows Unauthorized Organization Claims
CVE-2024-1722
Keycloak Denial of Service via account lockout
GHSA-vvf8-2h68-9475
Duplicate Advisory: Keycloak Open Redirect vulnerability
CVE-2021-3754
Keycloak's improper input validation allows using email as username
GHSA-j76j-rqwj-jmvv
Duplicate Advisory: Keycloak Session Fixation vulnerability
GHSA-8wm9-24qg-m5qj
Duplicate Advisory: Keycloak has a brute force login protection bypass
GHSA-5968-qw33-h47j
Duplicate Advisory: Keycloak vulnerable to reflected XSS via wildcard in OIDC redirect_uri
GHSA-j3x3-r585-4qhg
Duplicate Advisory: org.keycloak:keycloak-services has Inefficient Regular Expression Complexity
CVE-2022-2232
Keycloak vulnerable to LDAP Injection on UsernameForm Login
GHSA-4vrx-8phj-x3mg
Duplicate Advisory: Keycloak exposes sensitive information in Pushed Authorization Requests (PAR)
GHSA-mwm4-5qwr-g9pf
Keycloak is vulnerable to IDN homograph attack
CVE-2024-4629
Keycloak Services has a potential bypass of brute force protection
CVE-2023-6484
Keycloak vulnerable to log Injection during WebAuthn authentication or registration
CVE-2020-10776
Cross-site Scripting in keycloak
CVE-2014-3652
JBoss KeyCloak Open Redirect
CVE-2023-2422
Keycloak vulnerable to Improper Client Certificate Validation for OAuth/OpenID clients
CVE-2014-3709
JBoss Keycloak CSRF Vulnerability
CVE-2023-6134
Keycloak vulnerable to reflected XSS via wildcard in OIDC redirect_uri
CVE-2018-10894
Keycloak Authentication Error
CVE-2023-2585
Client Spoofing within the Keycloak Device Authorisation Grant
CVE-2022-4361
Keycloak vulnerable to cross-site scripting when validating URI-schemes on SAML and OIDC
CVE-2023-6291
The redirect_uri validation logic allows for bypassing explicitly allowed hosts that would otherwise be restricted
CVE-2022-1438
Keycloak vulnerable to Cross-site Scripting
CVE-2021-3424
Keycloak is vulnerable to IDN homograph attack
CVE-2014-3655
JBoss KeyCloak is vulnerable to soft token deletion via CSRF
Ready to move
Start Securing
Free, no credit card | First findings in minutes