org.keycloak:keycloak-services vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-1035Loworg.keycloak:keycloak-services: Keycloak does not validate and update refresh token usage atomicallyCVE-2025-14082Loworg.keycloak:keycloak-services: Keycloak Admin REST (Representational State Transfer) API does not properly enforce permissionsCVE-2025-12390Mediumorg.keycloak:keycloak-services: Keycloak vulnerable to session takeovers due to reuse of session identifiersCVE-2025-12110Mediumorg.keycloak:keycloak-services: Keycloak does not invalidate offline sessions when the offline_access scope is removedCVE-2025-11429Mediumorg.keycloak:keycloak-services: Keycloak does not invalidate sessions when "Remember Me" is disabledCVE-2025-8419Mediumorg.keycloak:keycloak-services: Keycloak SMTP Inject VulnerabilityCVE-2025-7784Mediumorg.keycloak:keycloak-services: Keycloak Privilege Escalation Vulnerability in Admin Console (FGAPv2 Enabled)CVE-2025-7365Mediumorg.keycloak:keycloak-services: Keycloak phishing attack via email verification step in first login flowCVE-2025-3910Mediumorg.keycloak:keycloak-services: Keycloak vulnerable to two factor authentication bypassCVE-2025-3501Highorg.keycloak:keycloak-services: Keycloak hostname verificationCVE-2025-2559Mediumorg.keycloak:keycloak-services: Keycloak Denial of Service (DoS) Vulnerability via JWT Token CacheCVE-2025-1391Mediumorg.keycloak:keycloak-services: Improper Authorization in Keycloak Organization Mapper Allows Unauthorized Organization Claims CVE-2024-10270Highorg.keycloak:keycloak-services: org.keycloak:keycloak-services has Inefficient Regular Expression ComplexityCVE-2024-7341Highorg.keycloak:keycloak-services: Keycloak has session fixation in Elytron SAML adaptersCVE-2024-8883Mediumorg.keycloak:keycloak-services: Keycloak has Vulnerable Redirect URI Validation Results in Open RedirectCVE-2024-4629Mediumorg.keycloak:keycloak-services: Keycloak Services has a potential bypass of brute force protectionCVE-2024-1722Loworg.keycloak:keycloak-services: Keycloak Denial of Service via account lockoutCVE-2021-3754Loworg.keycloak:keycloak-services: Keycloak's improper input validation allows using email as usernameCVE-2024-3656Highorg.keycloak:keycloak-services: Keycloak's admin API allows low privilege users to use administrative functionsCVE-2024-4540Highorg.keycloak:keycloak-services: Keycloak exposes sensitive information in Pushed Authorization Requests (PAR)CVE-2023-0657Loworg.keycloak:keycloak-services: Keycloak vulnerable to impersonation via logout token exchangeCVE-2023-6787Mediumorg.keycloak:keycloak-services: Keycloak vulnerable to session hijacking via re-authenticationCVE-2024-1132Highorg.keycloak:keycloak-services: Keycloak path traversal vulnerability in redirection validationCVE-2024-1249Highorg.keycloak:keycloak-services: Keycloak's unvalidated cross-origin messages in checkLoginIframe leads to DDoSCVE-2023-6484Mediumorg.keycloak:keycloak-services: Keycloak vulnerable to log Injection during WebAuthn authentication or registration

Stop the waste.
Protect your environment with Kodem.