RHSA-2024:10178HighCVSS 7.1

Red Hat Security Advisory: Red Hat build of Keycloak 26.0.6 Update

Published
November 21, 2024
Last Modified
August 4, 2026

🔗 CVE IDs covered (5)

📋 Description

CVE-2024-9666 — org.keycloak/keycloak-quarkus-server: Keycloak proxy header handling Denial-of-Service (DoS) vulnerability CVE-2024-10039 — keycloak-core: mTLS passthrough CVE-2024-10270 — org.keycloak:keycloak-services: Keycloak Denial of Service CVE-2024-10451 — org.keycloak:keycloak-quarkus-server: Sensitive Data Exposure in Keycloak Build Process CVE-2024-10492 — keycloak-quarkus-server: Keycloak path trasversal

🎯 Affected products1

  • Red Hat build of Keycloak 26.0.6

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258

🔗 References (8)