org.keycloak:keycloak-services vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-2092Highorg.keycloak:keycloak-services: Keycloak: Unauthorized access via improper validation of encrypted SAML assertionsCVE-2026-9795Highorg.keycloak:keycloak-services: Keycloak has privilege escalation via improper scope mapping enforcementCVE-2026-9803Mediumorg.keycloak:keycloak-services: Keycloak has an Out-of-bounds ReadCVE-2026-9802Mediumorg.keycloak:keycloak-services: Keycloak has Insufficient Session ExpirationCVE-2026-9798Mediumorg.keycloak:keycloak-services: Keycloak has an Authentication Bypass by Primary WeaknessCVE-2026-9793Mediumorg.keycloak:keycloak-services: Keycloak has an Improper Verification of Cryptographic Signature issueCVE-2026-9794Mediumorg.keycloak:keycloak-services: Keycloak Generates an Error Message Containing Sensitive InformationCVE-2026-9792Mediumorg.keycloak:keycloak-services: Keycloak Vulnerable to Improper Handling of Insufficient Permissions or PrivilegeCVE-2026-9791Mediumorg.keycloak:keycloak-server-spi-private: Keycloak Vulnerable to Incorrect AuthorizationCVE-2026-9704Mediumorg.keycloak:keycloak-server-spi-private: Keycloak Vulnerable to Improper Validation of Specified Quantity in InputCVE-2026-9689Mediumorg.keycloak:keycloak-services: Keycloak Services has Improper Validation of Consistency within InputCVE-2026-9087Mediumorg.keycloak:keycloak-services: Keycloak: Insufficient verification proof scoping enables identity provider account linking attack and account compromiseCVE-2026-7507Highorg.keycloak:keycloak-services: Keycloak: Session fixation in OIDC login flow that can lead to account takeoverCVE-2026-7504Highorg.keycloak:keycloak-services: Keycloak: Open redirect when using wildcard valid redirect URIs in KeycloakCVE-2026-7571Highorg.keycloak:keycloak-services: Keycloak: Access token disclosure and implicit flow bypass via forged client dataCVE-2026-4630Mediumorg.keycloak:keycloak-services: Keycloak Protection API allows authenticated clients to access and modify resources owned by other Resource ServersCVE-2026-37981Mediumorg.keycloak:keycloak-services: Keycloak Account Resources user lookup contains broken access controlCVE-2026-37982Mediumorg.keycloak:keycloak-services: Keycloak: Unauthorized account takeover via WebAuthn token replayCVE-2026-37979Mediumorg.keycloak:keycloak-services: Keycloak: Information disclosure via OIDC token introspection endpoint audience bypassCVE-2026-37978Mediumorg.keycloak:keycloak-services: Keycloak: Information Disclosure via evaluate-scopes Admin APICVE-2026-8922Mediumorg.keycloak:keycloak-services: Keycloak: Revoked Tokens Can Remain Active When Both Realm-Level and Client-Level `notBefore` Revocation Policies are ConfiguredCVE-2026-8830Mediumorg.keycloak:keycloak-services: Keycloak: Policy bypass during WebAuthn credential registration via client-side JavaScript manipulationCVE-2026-7500Mediumorg.keycloak:keycloak-services: Keycloak has a Forced Browsing issueCVE-2026-37980Mediumorg.keycloak:keycloak-services: Keycloak: Arbitrary code execution via Stored Cross-Site Scripting (XSS) in organization selection login pageCVE-2026-37977Loworg.keycloak:keycloak-services: Keycloak vulnerable to information disclosure via CORS header injection due to unvalidated JWT azp claim

Stop the waste.
Protect your environment with Kodem.