LOW 2.7 Maven
Keycloak Server-Side Request Forgery (SSRF) vulnerability
GHSA-fwhw-chw4-gh37 · CVE-2026-1518
Published · Modified
Description
A flaw was found in Keycloak’s CIBA feature where insufficient validation of client-configured backchannel notification endpoints could allow blind server-side requests to internal services.
Ready to move
Start Securing
Free, no credit card | First findings in minutes