org.keycloak:keycloak-services
Maven64 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting org.keycloak:keycloak-servicespage 1 of 2
- CVE-2014-3652MEDIUMCVSS 6.1EG 6.1✓ Fixed in 1.1.0.Beta12019-12-15
vulnerable: 1.0-alpha-1 ... 1.0.5.Final (19 versions)
JBoss KeyCloak: Open redirect vulnerability via failure to validate the redirect URL.
- CVE-2014-3655MEDIUMCVSS 4.3EG 4.3✓ Fixed in 1.0.2.Final2019-11-13
vulnerable: 1.0-alpha-1 ... 1.0.1.Final (15 versions)
JBoss KeyCloak is vulnerable to soft token deletion via CSRF
- CVE-2014-3709HIGHCVSS 8.8EG 8.8✓ Fixed in 1.0.3.Final2017-10-18
vulnerable: 1.0-alpha-1 ... 1.0.2.Final (16 versions)
The org.keycloak.services.resources.SocialResource.callback method in JBoss KeyCloak before 1.0.3.Final allows remote attackers to conduct cross-site request forgery (CSRF) attacks by leveraging lack of CSRF protection.
- CVE-2018-10894MEDIUMCVSS 5.4✓ Fixed in 4.4.0.Final2018-08-01
vulnerable: 1.0-alpha-1 ... 4.3.0.Final (91 versions)
It was found that SAML authentication in Keycloak 3.4.3.Final incorrectly authenticated expired certificates. A malicious user could use this to access unauthorized data or possibly conduct further attacks.
- CVE-2020-10776MEDIUMCVSS 4.8EG 4.8✓ Fixed in 12.0.02020-11-17
vulnerable: 1.0-alpha-1 ... 9.0.3 (117 versions)
A flaw was found in Keycloak before version 12.0.0, where it is possible to add unsafe schemes for the redirect_uri parameter. This flaw allows an attacker to perform a Cross-site scripting attack.
- CVE-2021-3424MEDIUMCVSS 5.3EG 5.3✓ Fixed in 18.0.02021-06-01
vulnerable: 1.0-alpha-1 ... 9.0.3 (135 versions)
A flaw was found in keycloak as shipped in Red Hat Single Sign-On 7.4 where IDN homograph attacks are possible. A malicious user can register himself with a name already registered and trick admin to grant him extra privileges.
- CVE-2021-3754MEDIUMCVSS 5.3EG 5.3✓ Fixed in 24.0.12022-08-26
vulnerable: 1.0-alpha-1 ... 9.0.3 (169 versions)
A flaw was found in keycloak where an attacker is able to register himself with the username same as the email ID of any existing user. This may cause trouble in getting password recovery email in case the user forgets the password.
- CVE-2021-4133HIGHCVSS 8.8EG 8.8✓ Fixed in 15.1.12022-01-25
vulnerable: 1.0-alpha-1 ... 9.0.3 (129 versions)
A flaw was found in Keycloak in versions from 12.0.0 and before 15.1.1 which allows an attacker with any existing user account to create new default user accounts via the administrative REST API even when new user registration is disabled.
- CVE-2022-1245CRITICALCVSS 9.8EG 9.8✓ Fixed in 18.0.02022-07-08
vulnerable: 1.0-alpha-1 ... 9.0.3 (135 versions)
A privilege escalation flaw was found in the token exchange feature of keycloak. Missing authorization allows a client application holding a valid access token to exchange tokens for any target client by passing the client_id of the target…
- CVE-2022-1274MEDIUMCVSS 5.4EG 5.4✓ Fixed in 20.0.52023-03-29
vulnerable: 1.0-alpha-1 ... 9.0.3 (147 versions)
A flaw was found in Keycloak in the execute-actions-email endpoint. This issue allows arbitrary HTML to be injected into emails sent to Keycloak users and can be misused to perform phishing or other attacks against users.
- CVE-2022-1438MEDIUMCVSS 6.4EG 6.42023-09-20
vulnerable: 1.0-alpha-1 ... 9.0.3 (149 versions)
A flaw was found in Keycloak. Under specific circumstances, HTML entities are not sanitized during user impersonation, resulting in a Cross-site scripting (XSS) vulnerability.
- CVE-2022-2232HIGHCVSS 7.5EG 7.5✓ Fixed in 23.0.12024-11-14
vulnerable: 1.0-alpha-1 ... 9.0.3 (161 versions)
A flaw was found in the Keycloak package. This flaw allows an attacker to utilize an LDAP injection to bypass the username lookup or potentially perform other malicious actions.
- CVE-2022-4361CRITICALCVSS 10.0EG 10.0✓ Fixed in 21.1.22023-07-07
vulnerable: 1.0-alpha-1 ... 9.0.3 (153 versions)
Keycloak, an open-source identity and access management solution, has a cross-site scripting (XSS) vulnerability in the SAML or OIDC providers. The vulnerability can allow an attacker to execute malicious scripts by setting the AssertionCo…
- CVE-2023-0264MEDIUMCVSS 5.0EG 5.0✓ Fixed in 21.0.12023-08-04
vulnerable: 1.0-alpha-1 ... 9.0.3 (149 versions)
A flaw was found in Keycloaks OpenID Connect user authentication, which may incorrectly authenticate requests. An authenticated attacker who could obtain information from a user request within the same realm could use that data to imperson…
- CVE-2023-0657LOWCVSS 3.4EG 3.4✓ Fixed in 24.0.32024-11-17
vulnerable: 23.0.0 ... 24.0.2 (11 versions)
A flaw was found in Keycloak. This issue occurs due to improperly enforcing token types when validating signatures locally. This could allow an authenticated attacker to exchange a logout token for an access token and possibly gain access …
- CVE-2023-2422MEDIUMCVSS 5.5EG 5.5✓ Fixed in 21.1.22023-10-04
vulnerable: 1.0-alpha-1 ... 9.0.3 (153 versions)
A flaw was found in Keycloak. A Keycloak server configured to support mTLS authentication for OAuth/OpenID clients does not properly verify the client certificate chain. A client that possesses a proper certificate can authorize itself as …
- CVE-2023-2585LOWCVSS 3.5EG 3.5✓ Fixed in 21.1.22023-12-21
vulnerable: 1.0-alpha-1 ... 9.0.3 (153 versions)
Keycloak's device authorization grant does not correctly validate the device code and client ID. An attacker client could abuse the missing validation to spoof a client consent request and trick an authorization admin into granting consent…
- CVE-2023-3597MEDIUMCVSS 5.0EG 5.0✓ Fixed in 24.0.32024-04-25
vulnerable: 23.0.0 ... 24.0.2 (11 versions)
A flaw was found in Keycloak, where it does not correctly validate its client step-up authentication in org.keycloak.authentication. This flaw allows a remote user authenticated with a password to register a false second authentication fac…
- CVE-2023-6134MEDIUMCVSS 4.6EG 4.6✓ Fixed in 23.0.32023-12-14
vulnerable: 1.0-alpha-1 ... 9.0.3 (163 versions)
A flaw was found in Keycloak that prevents certain schemes in redirects, but permits them if a wildcard is appended to the token. This issue could allow an attacker to submit a specially crafted request leading to cross-site scripting (XSS…
- CVE-2023-6291HIGHCVSS 7.1EG 7.1✓ Fixed in 23.0.32024-01-26
vulnerable: 1.0-alpha-1 ... 9.0.3 (163 versions)
A flaw was found in the redirect_uri validation logic in Keycloak. This issue may allow a bypass of otherwise explicitly allowed hosts. A successful attack may lead to an access token being stolen, making it possible for the attacker to im…
- CVE-2023-6484MEDIUMCVSS 5.3EG 5.3✓ Fixed in 23.0.52024-04-25
vulnerable: 23.0.0, 23.0.1, 23.0.2, 23.0.3, 23.0.4
A log injection flaw was found in Keycloak. A text string may be injected through the authentication form when using the WebAuthn authentication mode. This issue may have a minor impact to the logs integrity.
- CVE-2023-6544MEDIUMCVSS 5.4EG 5.4✓ Fixed in 24.0.32024-04-25
vulnerable: 23.0.0 ... 24.0.2 (11 versions)
A flaw was found in the Keycloak package. This issue occurs due to a permissive regular expression hardcoded for filtering which allows hosts to register a dynamic client. A malicious user with enough information about the environment coul…
- CVE-2023-6717MEDIUMCVSS 6.0EG 6.0✓ Fixed in 24.0.32024-04-25
vulnerable: 23.0.0 ... 24.0.2 (11 versions)
A flaw was found in the SAML client registration in Keycloak that could allow an administrator to register malicious JavaScript URIs as Assertion Consumer Service POST Binding URLs (ACS), posing a Cross-Site Scripting (XSS) risk. This issu…
- CVE-2023-6787MEDIUMCVSS 6.5EG 6.5✓ Fixed in 24.0.32024-04-25
vulnerable: 23.0.0 ... 24.0.2 (11 versions)
A flaw was found in Keycloak that occurs from an error in the re-authentication mechanism within org.keycloak.authentication. This flaw allows hijacking an active Keycloak session by triggering a new authentication process with the query p…
- CVE-2024-10270MEDIUMCVSS 6.5EG 6.5✓ Fixed in 26.0.62024-11-25
vulnerable: 25.0.0 ... 26.0.5 (13 versions)
A vulnerability was found in the Keycloak-services package. If untrusted data is passed to the SearchQueryUtils method, it could lead to a denial of service (DoS) scenario by exhausting system resources due to a Regex complexity.
- CVE-2024-1132HIGHCVSS 8.1EG 8.1✓ Fixed in 24.0.32024-04-17
vulnerable: 23.0.0 ... 24.0.2 (11 versions)
A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. This issue could allow an attacker to construct a malicious request to bypass validation and access other URLs and sensitive information within …
- CVE-2024-1249HIGHCVSS 7.4EG 7.4✓ Fixed in 24.0.32024-04-17
vulnerable: 23.0.0 ... 24.0.2 (11 versions)
A flaw was found in Keycloak's OIDC component in the "checkLoginIframe," which allows unvalidated cross-origin messages. This flaw allows attackers to coordinate and send millions of requests in seconds using simple code, significantly imp…
- CVE-2024-1722LOWCVSS 3.7EG 3.7✓ Fixed in 24.0.02024-02-29
vulnerable: 1.0-alpha-1 ... 9.0.3 (168 versions)
A flaw was found in Keycloak. In certain conditions, this issue may allow a remote unauthenticated attacker to block other accounts from logging in.
- CVE-2024-2419HIGHCVSS 7.1EG 7.1✓ Fixed in 24.0.32024-04-17
vulnerable: 23.0.0 ... 24.0.2 (11 versions)
A flaw was found in Keycloak's redirect_uri validation logic. This issue may allow a bypass of otherwise explicitly allowed hosts. A successful attack may lead to the theft of an access token, making it possible for the attacker to imperso…
- CVE-2024-3656HIGHCVSS 8.1EG 9.0✓ Fixed in 24.0.52024-10-09
vulnerable: 1.0-alpha-1 ... 9.0.3 (173 versions)
A flaw was found in Keycloak. Certain endpoints in Keycloak's admin REST API allow low-privilege users to access administrative functionalities. This flaw allows users to perform actions reserved for administrators, potentially leading to …
- CVE-2024-4540HIGHCVSS 7.5EG 7.5✓ Fixed in 24.0.52024-06-03
vulnerable: 1.0-alpha-1 ... 9.0.3 (173 versions)
A flaw was found in Keycloak in OAuth 2.0 Pushed Authorization Requests (PAR). Client-provided parameters were found to be included in plain text in the KC_RESTART cookie returned by the authorization server's HTTP response to a `request_u…
- CVE-2024-4629MEDIUMCVSS 6.5EG 6.5✓ Fixed in 25.0.42024-09-03
vulnerable: 25.0.0, 25.0.1, 25.0.2, 25.0.3
A vulnerability was found in Keycloak. This flaw allows attackers to bypass brute force protection by exploiting the timing of login attempts. By initiating multiple login requests simultaneously, attackers can exceed the configured limits…
- CVE-2024-7341HIGHCVSS 7.1EG 7.1✓ Fixed in 25.0.52024-09-09
vulnerable: 25.0.0, 25.0.1, 25.0.2, 25.0.3, 25.0.4
A session fixation issue was discovered in the SAML adapters provided by Keycloak. The session ID and JSESSIONID cookie are not changed at login time, even when the turnOffChangeSessionIdOnLogin option is configured. This flaw allows an at…
- CVE-2024-8883MEDIUMCVSS 6.1EG 6.1✓ Fixed in 25.0.62024-09-19
vulnerable: 25.0.0 ... 25.0.5 (6 versions)
A misconfiguration flaw was found in Keycloak. This issue can allow an attacker to redirect users to an arbitrary URL if a 'Valid Redirect URI' is set to http://localhost or http://127.0.0.1, enabling sensitive information such as authoriz…
- CVE-2025-11429MEDIUMCVSS 5.4EG 5.4✓ Fixed in 26.2.112025-10-23
vulnerable: 1.0-alpha-1 ... 9.0.3 (202 versions)
A flaw was found in Keycloak. Keycloak does not immediately enforce the disabling of the "Remember Me" realm setting on existing user sessions. Sessions created while "Remember Me" was active retain their extended session lifetime until th…
- CVE-2025-12110MEDIUMCVSS 5.4EG 5.4✓ Fixed in 26.2.32025-10-23
vulnerable: 1.0-alpha-1 ... 9.0.3 (199 versions)
A flaw was found in Keycloak. An offline session continues to be valid when the offline_access scope is removed from the client. The refresh token is accepted and you can continue to request new tokens for the session. As it can lead to a …
- CVE-2025-12390MEDIUMCVSS 6.0EG 6.0✓ Fixed in 26.0.02025-10-28
vulnerable: 1.0-alpha-1 ... 9.0.3 (181 versions)
A flaw was found in Keycloak. In Keycloak where a user can accidentally get access to another user's session if both use the same device and browser. This happens because Keycloak sometimes reuses session identifiers and doesn’t clean up…
- CVE-2025-13881LOWCVSS 2.7EG 2.7✓ Fixed in 26.4.92026-02-02
vulnerable: 1.0-alpha-1 ... 9.0.3 (216 versions)
A flaw was found in Keycloak Admin API. This vulnerability allows an administrator with limited privileges to retrieve sensitive custom attributes via the /unmanagedAttributes endpoint, bypassing User Profile visibility settings.
- CVE-2025-1391MEDIUMCVSS 5.4EG 5.4✓ Fixed in 26.0.102025-02-17
vulnerable: 1.0-alpha-1 ... 9.0.3 (190 versions)
A flaw was found in the Keycloak organization feature, which allows the incorrect assignment of an organization to a user if their username or email matches the organization’s domain pattern. This issue occurs at the mapper level, leadin…
- CVE-2025-14082LOWCVSS 2.7EG 2.7✓ Fixed in 26.5.02025-12-10
vulnerable: 1.0-alpha-1 ... 9.0.3 (216 versions)
A flaw was found in Keycloak Admin REST (Representational State Transfer) API. This vulnerability allows information disclosure of sensitive role metadata via insufficient authorization checks on the /admin/realms/{realm}/roles endpoint.
- CVE-2025-14083LOWCVSS 2.7EG 2.72026-01-21
vulnerable: 1.0-alpha-1 ... 9.0.3 (202 versions)
A flaw was found in the Keycloak Admin REST API. This vulnerability allows the exposure of backend schema and rules, potentially leading to targeted attacks or privilege escalation via improper access control.
- CVE-2025-14559MEDIUMCVSS 6.5EG 6.5✓ Fixed in 26.4.92026-01-21
vulnerable: 1.0-alpha-1 ... 9.0.3 (216 versions)
A flaw was found in the keycloak-services component of Keycloak. This vulnerability allows the issuance of access and refresh tokens for disabled users, leading to unauthorized use of previously revoked privileges, via a business logic vul…
- CVE-2025-14778MEDIUMCVSS 5.4EG 5.4✓ Fixed in 26.4.92026-02-09
vulnerable: 26.3.0 ... 26.4.7 (14 versions)
A flaw was found in Keycloak. A significant Broken Access Control vulnerability exists in the UserManagedPermissionService (UMA Protection API). When updating or deleting a UMA policy associated with multiple resources, the authorization c…
- CVE-2025-2559MEDIUMCVSS 4.9EG 4.92025-03-25
vulnerable: 1.0-alpha-1 ... 9.0.3 (195 versions)
A flaw was found in Keycloak. When the configuration uses JWT tokens for authentication, the tokens are cached until expiration. If a client uses JWT tokens with an excessively long expiration time, for example, 24 or 48 hours, the cache c…
- CVE-2025-3501HIGHCVSS 8.2EG 8.2✓ Fixed in 26.2.22025-04-29
vulnerable: 1.0-alpha-1 ... 9.0.3 (198 versions)
A flaw was found in Keycloak. By setting a verification policy to 'ALL', the trust store certificate verification is skipped, which is unintended.
- CVE-2025-7365HIGHCVSS 7.1EG 7.1✓ Fixed in 26.2.62025-07-10
vulnerable: 26.2.0 ... 26.2.5 (6 versions)
A flaw was found in Keycloak. When an authenticated attacker attempts to merge accounts with another existing account during an identity provider (IdP) login, the attacker will subsequently be prompted to "review profile" information. This…
- CVE-2025-7784MEDIUMCVSS 6.5EG 6.5✓ Fixed in 26.2.62025-07-18
vulnerable: 26.2.0 ... 26.2.5 (6 versions)
A flaw was found in the Keycloak identity and access management system when Fine-Grained Admin Permissions(FGAPv2) are enabled. An administrative user with the manage-users role can escalate their privileges to realm-admin due to improper …
- CVE-2026-1035LOWCVSS 3.1EG 3.12026-01-21
vulnerable: 1.0-alpha-1 ... 9.0.3 (202 versions)
A flaw was found in the Keycloak server during refresh token processing, specifically in the TokenManager class responsible for enforcing refresh token reuse policies. When strict refresh token rotation is enabled, the validation and updat…
- CVE-2026-1190LOWCVSS 3.1EG 3.12026-01-26
vulnerable: 1.0-alpha-1 ... 9.0.3 (219 versions)
A flaw was found in Keycloak's SAML brokering functionality. When Keycloak is configured as a client in a Security Assertion Markup Language (SAML) setup, it fails to validate the `NotOnOrAfter` timestamp within the `SubjectConfirmationDat…
- CVE-2026-1486HIGHCVSS 8.8EG 8.8✓ Fixed in 26.4.92026-02-09
vulnerable: 1.0-alpha-1 ... 9.0.3 (216 versions)
A flaw was found in Keycloak. A vulnerability exists in the jwt-authorization-grant flow where the server fails to verify if an Identity Provider (IdP) is enabled before issuing tokens. The issuer lookup mechanism (lookupIdentityProviderFr…
Check whether org.keycloak:keycloak-services is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for org.keycloak:keycloak-services CVEs against the assets you own.
Start Free Scan →