RHSA-2026:19594HighCVSS 8.1

Red Hat Security Advisory: Red Hat build of Keycloak 26.2.16 Security Update

Published
May 20, 2026
Last Modified
October 6, 2026

🔗 CVE IDs covered (3)

📋 Description

CVE-2026-7307 — keycloak: Keycloak: Denial of Service via specially crafted SAML input CVE-2026-7504 — org.keycloak/keycloak-services: Open redirect when using wildcard valid redirect URIs in Keycloak CVE-2026-7507 — org.keycloak/keycloak-services: Session fixation in OIDC login flow that can lead to account takeover

🎯 Affected products1

  • Red Hat build of Keycloak 26.2.16

✅ Remediation

Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. Workaround: To mitigate this vulnerability, restrict network access to the Keycloak SAML endpoint to trusted networks and clients. Implement firewall rules to limit inbound connections to the Keycloak service port (e.g., 8080) from untrusted sources. If the SAML protocol is not required for your deployment, consider disabling it to eliminate the attack surface. Applying these network restrictions or configuration changes may necessitate a restart or reload of the Keycloak service, which could temporarily affect its availability. Workaround: To mitigate this vulnerability, Red Hat recommends avoiding the use of wildcard characters in the "Valid Redirect URIs" field for clients within Keycloak. Instead, explicitly list all allowed redirect URIs. Review all client configurations to ensure that wildcards are not used unless absolutely necessary, and if used, ensure that the client application is robust against open redirect vulnerabilities. Changes to client configurations in Keycloak may require a restart or reload of the Keycloak service to take effect, which could impact active user sessions. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

🔗 References (3)