Launch Week Day 1: Announcing Security Design Review
HIGH 7.5 Maven

Keycloak: Denial of Service via specially crafted SAML input

GHSA-p5mv-gj8j-xqgf · CVE-2026-7307

Published · Modified

Description

A flaw was found in Keycloak. A remote, unauthenticated attacker can send a specially crafted XML input to the Security Assertion Markup Language (SAML) endpoint. This malicious input can cause high CPU usage and worker thread starvation, leading to a Denial of Service (DoS) where the server becomes unavailable.

Ready to move

Start Securing

Free, no credit card | First findings in minutes