org.keycloak:keycloak-services vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-37977Loworg.keycloak:keycloak-services: Keycloak vulnerable to information disclosure via CORS header injection due to unvalidated JWT azp claimCVE-2026-4634Highorg.keycloak:keycloak-services: Keycloak: Application-Level DoS via Scope ProcessingCVE-2026-4282Highorg.keycloak:keycloak-services: Keycloak: Privilege escalation via forged authorization codes due to SingleUseObjectProvider isolation flawCVE-2026-4325Mediumorg.keycloak:keycloak-services: Keycloak: Replay of action tokens via improper handling of single-use entriesCVE-2026-4636Highorg.keycloak:keycloak-services: Keycloak: UMA Policy Resource Injection Allows Unauthorized Cross-User Permission GrantsCVE-2026-3872Highorg.keycloak:keycloak-services: Keycloak: Redirect URI validation bypass via ..;/ path traversal in OIDC auth endpointCVE-2026-3190Mediumorg.keycloak:keycloak-server-spi-private: Keycloak: Missing Role Enforcement on UMA 2.0 Permission Ticket Endpoint Leads to Information DisclosureCVE-2026-3121Mediumorg.keycloak:keycloak-services: Keycloak: manage-clients permission escalates to full realm admin accessCVE-2026-4874Loworg.keycloak:keycloak-services: Keycloak Server-Side Request Forgery via OIDC token endpoint manipulationCVE-2026-4633Loworg.keycloak:keycloak-services: Keycloak's identity-first login flow exposes user informationCVE-2026-4628Mediumorg.keycloak:keycloak-services: Keycloak has Improper Access Control that allows attackers with valid credentials to bypass the allowRemoteResourceManagement=falseCVE-2026-2575Mediumorg.keycloak:keycloak-saml-adapter-core: Keycloak: Denial of Service due to excessive SAMLRequest decompressionCVE-2026-2603Highorg.keycloak:keycloak-services: Keycloak: Unauthorized authentication via disabled SAML Identity ProviderCVE-2026-3429Mediumorg.keycloak:keycloak-services: Keycloak: Improper Access Control Leading to MFA Deletion and Account Takeover in Keycloak Account REST APICVE-2026-3911Loworg.keycloak:keycloak-services: Keycloak: Information disclosure of disabled user attributes via administrative endpointCVE-2026-3009Highorg.keycloak:keycloak-services: Keycloak allows authentication using an Identity Provider (IdP) even after it has been disabled by an administratorCVE-2025-12150Loworg.keycloak:keycloak-services: Keycloak REST Services has a WebAuthn Attestation Statement Verification BypassCVE-2026-2733Loworg.keycloak:keycloak-services: Keycloak: Missing Check on Disabled Client for Docker Registry ProtocolCVE-2025-14778Mediumorg.keycloak:keycloak-services: Keycloak Affected by Broken Access Control Vulnerability in the UserManagedPermissionServiceCVE-2026-1486Highorg.keycloak:keycloak-services: Keycloak fails to verify if an Identity Provider (IdP) is enabled before issuing tokensCVE-2026-1529Highorg.keycloak:keycloak-services: Keycloak affected by improper invitation token validationCVE-2025-13881Loworg.keycloak:keycloak-services: Keycloak Admin API allows an administrator with limited privileges to retrieve sensitive custom attributesCVE-2026-1190Loworg.keycloak:keycloak-services: Keycloak's missing timestamp validation allows attackers to extend SAML response validity periodsCVE-2025-14083Loworg.keycloak:keycloak-services: Keycloak Admin REST API exposes backend schema and rulesCVE-2025-14559Mediumorg.keycloak:keycloak-services: Keycloak services allows the issuance of access and refresh tokens for disabled users

Stop the waste.
Protect your environment with Kodem.