Sicherheit
Security
All tracked CVEs and security advisories — sorted by date or severity. Each entry links to the official source. The plain-text explanations are generated automatically — the source remains authoritative.
| CVE / GHSA | Item | Vertical | Severity | Date |
|---|---|---|---|---|
| GHSA-pxh5-6rrc-8rjv Source OpenTofu can enter an infinite loop when installing modules or providers from malicious servers, causing the installation process to hang and depleting system resources. |
OpenTofu | OS & platform | Low | 07.06.2026 |
| CVE-2024-4629 Source Keycloak has a vulnerability in its brute force protection where attackers can make more password guessing attempts than configured limits by launching parallel login attempts, making user accounts easier to compromise. |
Keycloak | OS & platform | Medium | 07.06.2026 |
| CVE-2024-1722 Source In Keycloak, users with email-like usernames can be locked out by other users when self-registration is enabled in the realm. |
Keycloak | OS & platform | Low | 07.06.2026 |
| CVE-2021-3754 Source Keycloak allows using email addresses as usernames without checking if an account with that email already exists, which can prevent users from logging in or resetting their passwords. |
Keycloak | OS & platform | Low | 07.06.2026 |
| CVE-2024-5967 Source A vulnerability in Keycloak allows administrators to modify LDAP connection settings and redirect configured credentials to a server they control, potentially exposing domain authentication credentials to attackers. |
Keycloak | OS & platform | Low | 07.06.2026 |
| CVE-2024-7341 Source Keycloak's SAML adapters fail to properly change session IDs during login, allowing attackers to hijack existing sessions and impersonate legitimate users after authentication. |
Keycloak | OS & platform | High | 07.06.2026 |
| CVE-2024-8883 Source A misconfiguration in Keycloak allows attackers to redirect users to arbitrary websites when localhost URLs are configured as valid redirect addresses. This can lead to theft of authorization codes and hijacking of user sessions. |
Keycloak | OS & platform | Medium | 07.06.2026 |
| CVE-2024-8698 Source A vulnerability in Keycloak's SAML signature validation allows attackers to create forged authentication responses that bypass security checks, potentially leading to privilege escalation or identity impersonation attacks. |
Keycloak | OS & platform | High | 07.06.2026 |
| CVE-2024-7318 Source In Keycloak, an expired one-time passcode remains valid twice as long as intended when using FreeOTP, giving attackers a larger time window to compromise accounts. |
Keycloak | OS & platform | Medium | 07.06.2026 |
| CVE-2024-10451 Source Keycloak accidentally stores sensitive data like passwords in bytecode during the build process, making this information accessible at runtime and potentially exposing confidential data. |
Keycloak | OS & platform | Medium | 07.06.2026 |
| CVE-2024-10270 Source A vulnerability in Keycloak allows attackers to crash the server through complex regular expressions when untrusted data is processed, causing denial of service. |
Keycloak | OS & platform | Medium | 07.06.2026 |
| CVE-2024-10492 Source A vulnerability in Keycloak allows privileged users to read sensitive information from Vault files outside the intended context. Attackers need existing high-level access rights to the Keycloak server. |
Keycloak | OS & platform | Low | 07.06.2026 |
| CVE-2024-9666 Source Keycloak version 26 and earlier can be subjected to denial-of-service attacks through manipulated proxy headers that cause the system to perform costly DNS operations, potentially blocking the service. |
Keycloak | OS & platform | Medium | 07.06.2026 |
| CVE-2024-10039 Source A vulnerability in Keycloak allows attackers on the local network to impersonate any user or client when mTLS authentication is used through a reverse proxy without pass-through TLS termination. |
Keycloak | OS & platform | High | 07.06.2026 |
| CVE-2024-11734 Source A vulnerability in Keycloak allows administrators with realm settings permissions to crash the service by inserting newlines into security headers, preventing users from accessing applications that rely on Keycloak for authentication. |
Keycloak | OS & platform | Medium | 07.06.2026 |
| CVE-2024-11736 Source Keycloak administrators can access confidential server environment variables and system properties by using special placeholders in configurable URLs, potentially exposing sensitive information. |
Keycloak | OS & platform | Medium | 07.06.2026 |
| CVE-2024-10973 Source In Keycloak, a configuration option for encrypted communication between servers doesn't work properly, causing data transmission to occur unencrypted instead of being secured as intended. |
Keycloak | OS & platform | Medium | 07.06.2026 |
| CVE-2025-0604 Source Keycloak fails to properly verify Active Directory account status after password resets, potentially allowing users with expired or disabled accounts to still authenticate successfully. |
Keycloak | OS & platform | Medium | 07.06.2026 |
| CVE-2025-1391 Source Keycloak incorrectly assigns users to organizations based only on email or username patterns. This can allow attackers to impersonate organization members when self-registration is enabled. |
Keycloak | OS & platform | Medium | 07.06.2026 |
| CVE-2025-3501 Source Keycloak incorrectly skips certificate verification when a specific verification policy is set to 'ALL', potentially allowing insecure connections to be established. |
Keycloak | OS & platform | High | 07.06.2026 |
| CVE-2025-3910 Source A vulnerability in Keycloak allows users to bypass required security measures such as setting up two-factor authentication. |
Keycloak | OS & platform | Medium | 07.06.2026 |
| CVE-2025-7365 Source In Keycloak, attackers can change their email address to a victim's during first login via Identity Provider, causing a verification email to be sent to the victim that grants account access if clicked. |
Keycloak | OS & platform | Medium | 07.06.2026 |
| CVE-2025-7784 Source A vulnerability in Keycloak allows administrators with limited privileges to grant themselves higher permissions, thereby gaining full access to system configuration and user data. |
Keycloak | OS & platform | Medium | 07.06.2026 |
| CVE-2025-8419 Source Keycloak users can send unwanted emails through the server by using special characters during email registration, which could serve as a starting point for further attacks. |
Keycloak | OS & platform | Medium | 07.06.2026 |
| CVE-2025-10044 Source A vulnerability in Keycloak's user console allows attackers to inject fake error messages through URL parameters that are then displayed in the trusted user interface, enabling phishing attacks to deceive users. |
Keycloak | OS & platform | Medium | 07.06.2026 |
| CVE-2025-9162 Source A vulnerability in Keycloak allows attackers to inject malicious code into realm import documents by exploiting the placeholder substitution feature. This can lead to unintended consequences within the Keycloak environment. |
Keycloak | OS & platform | Medium | 07.06.2026 |
| CVE-2025-11419 Source Keycloak servers can be overwhelmed by repeated TLS connection requests from attackers due to a Java default setting that allows harmful renegotiations. This can crash the service without attackers needing to authenticate themselves. |
Keycloak | OS & platform | High | 07.06.2026 |
| CVE-2025-10939 Source A vulnerability in Keycloak allows attackers to access the admin area through manipulated paths, even when it should be protected by a proxy configuration. |
Keycloak | OS & platform | Low | 07.06.2026 |
| CVE-2025-11538 Source Keycloak server in debug mode binds the debug port to all network interfaces, allowing attackers on the local network to achieve remote code execution. |
Keycloak | OS & platform | Medium | 07.06.2026 |
| CVE-2025-13467 Source A vulnerability in Keycloak's LDAP user federation allows authenticated administrators to trigger unsafe Java object deserialization through malicious LDAP server configurations, potentially leading to code execution. |
Keycloak | OS & platform | Medium | 07.06.2026 |
| CVE-2026-2092 Source A security flaw in Keycloak allows attackers to impersonate arbitrary users by sending manipulated SAML messages with encrypted assertions, leading to unauthorized access and potential data exposure. |
Keycloak | OS & platform | High | 07.06.2026 |
| CVE-2021-32001 Source A vulnerability in k3s causes cluster encryption data to be secured with a weak key when no token is specified during creation, allowing attackers with database access to decrypt sensitive cluster keys. |
k3s | OS & platform | Medium | 07.06.2026 |
| CVE-2023-32187 Source A vulnerability in K3s allows attackers to bloat the TLS certificate through port 6443 without authentication until it becomes so large that new connections fail, causing a denial of service. |
k3s | OS & platform | High | 07.06.2026 |
| CVE-2026-54250 Source A vulnerability in K3s allows attackers to overwrite arbitrary files on the system through malicious zip archives when restoring etcd snapshots. |
k3s | OS & platform | Medium | 07.06.2026 |
| CVE-2020-11013 Source A vulnerability in Helm 3.0.0-3.1.2 allows malicious chart authors to secretly retrieve cluster information even though the 'helm template' command should not connect to any cluster. |
Helm | OS & platform | Low | 07.06.2026 |
| CVE-2020-7919 Source A vulnerability in Helm's underlying Go cryptography library can cause crashes on 32-bit systems when processing malformed X.509 certificates, leading to denial of service attacks. |
Helm | OS & platform | High | 07.06.2026 |
| CVE-2020-4053 Source A vulnerability in Helm 3.0.0-3.2.3 allows malicious plugin authors to overwrite files outside the intended directory through manipulated archives, potentially enabling code execution or compromising sensitive data. |
Helm | OS & platform | Low | 07.06.2026 |
| CVE-2020-15184 Source A vulnerability in Helm allows attackers to inject malicious content through the improperly validated alias field in Chart.yaml files. |
Helm | OS & platform | Low | 07.06.2026 |
| CVE-2020-15185 Source Helm repositories can contain duplicate chart entries where the last one is used, allowing attackers with write access to the index file to inject malicious charts. |
Helm | OS & platform | Low | 07.06.2026 |
| CVE-2020-15186 Source A vulnerability in Helm allows malicious plugin authors to use unsafe characters in plugin names, enabling them to impersonate other plugins or manipulate help output. |
Helm | OS & platform | Low | 07.06.2026 |
| CVE-2020-15187 Source A vulnerability in Helm allows attackers with write access to plugin repositories or through man-in-the-middle attacks to execute malicious code on the local system by exploiting duplicate plugin entries. |
Helm | OS & platform | Low | 07.06.2026 |
| CVE-2021-21303 Source Helm, a Kubernetes package manager, fails to properly sanitize input data from chart versions, repository files, and plugin files, allowing attackers to inject malicious characters that can manipulate or obscure terminal output. |
Helm | OS & platform | Low | 07.06.2026 |
| CVE-2021-32690 Source Helm, a Kubernetes package manager, incorrectly forwarded repository username and password credentials to other domains when retrieving chart archives from different servers. |
Helm | OS & platform | Medium | 07.06.2026 |
| CVE-2022-36055 Source A vulnerability in Helm's strvals package allows attackers to cause an out-of-memory crash that cannot be recovered from by providing specially crafted input strings that create large data structures. |
Helm | OS & platform | Medium | 07.06.2026 |
| CVE-2022-23526 Source A vulnerability in Helm's chartutil package can cause memory violations through specially crafted JSON schema files, leading to application crashes and enabling denial-of-service attacks. |
Helm | OS & platform | Medium | 07.06.2026 |
| CVE-2022-23525 Source A vulnerability in Helm's _repo_ package can cause memory violations through specially crafted repository index files, leading to application crashes and enabling denial-of-service attacks. |
Helm | OS & platform | Medium | 07.06.2026 |
| CVE-2022-23524 Source A vulnerability in the Helm package manager allows attackers to cause a stack overflow through specially crafted input, crashing the application in a way that cannot be recovered from. |
Helm | OS & platform | Medium | 07.06.2026 |
| CVE-2023-25165 Source A vulnerability in Helm allows malicious charts to leak sensitive data to DNS servers through the getHostByName function, potentially exposing confidential information during chart processing. |
Helm | OS & platform | Low | 07.06.2026 |
| CVE-2024-25620 Source A vulnerability in Helm allows malicious charts to save files outside the intended directory by using relative paths in the chart name. |
Helm | OS & platform | Medium | 07.06.2026 |
| CVE-2024-26147 Source A vulnerability in Helm causes program crashes when processing corrupted or incomplete YAML configuration files. Attackers can use malicious plugins or repository files to crash Helm commands and disrupt availability. |
Helm | OS & platform | Medium | 07.06.2026 |