GHSA-p5mv-gj8j-xqgfHighCVSS 7.5

A flaw was found in Keycloak. A remote, unauthenticated attacker can send a specially crafted XML...

Published
May 19, 2026
Last Modified
May 20, 2026

🔗 CVE IDs covered (1)

📋 Description

A flaw was found in Keycloak. A remote, unauthenticated attacker can send a specially crafted XML input to the Security Assertion Markup Language (SAML) endpoint. This malicious input can cause high CPU usage and worker thread starvation, leading to a Denial of Service (DoS) where the server becomes unavailable.

🔗 References (8)