28,679 Entries 2,229 Sources 5 Verticals Last sync 11 minutes Live
OS & platform

Keycloak

Red Hat
26.6.3 frisch latest release
04.06.2026

Upgrade assessment

Sicherheitsrelevant

Zeitnah aktualisieren

30 CVE(s) zuletzt, höchste Schwere: hoch

Derived automatically from release, repo and CVE data — no judgment by a language model.

Specsattributes
gh_etagW/"f486f45fe57d15abeed776e0e1e257d42a21e673c00c3f7a2c7e8228b7c7fa11"
eol_productkeycloak
gh_checked_at2026-06-08T02:00:46.648547+00:00
Timelinealle Einträge
Type Ereignis · Quelle Value · Time
CVE
OS & platform Medium

Keycloak has a vulnerability in its brute force protection where attackers can make more password guessing attempts than configured limits by launching parallel login attempts, making user accounts easier to compromise.

CVE-2024-4629
07.06.2026
CVE
OS & platform Low

In Keycloak, users with email-like usernames can be locked out by other users when self-registration is enabled in the realm.

CVE-2024-1722
07.06.2026
CVE
OS & platform Low

Keycloak allows using email addresses as usernames without checking if an account with that email already exists, which can prevent users from logging in or resetting their passwords.

CVE-2021-3754
07.06.2026
CVE
OS & platform Low

A vulnerability in Keycloak allows administrators to modify LDAP connection settings and redirect configured credentials to a server they control, potentially exposing domain authentication credentials to attackers.

CVE-2024-5967
07.06.2026
CVE
OS & platform High

Keycloak's SAML adapters fail to properly change session IDs during login, allowing attackers to hijack existing sessions and impersonate legitimate users after authentication.

CVE-2024-7341
07.06.2026
CVE
OS & platform Medium

A misconfiguration in Keycloak allows attackers to redirect users to arbitrary websites when localhost URLs are configured as valid redirect addresses. This can lead to theft of authorization codes and hijacking of user sessions.

CVE-2024-8883
07.06.2026
CVE
OS & platform High

A vulnerability in Keycloak's SAML signature validation allows attackers to create forged authentication responses that bypass security checks, potentially leading to privilege escalation or identity impersonation attacks.

CVE-2024-8698
07.06.2026
CVE
OS & platform Medium

In Keycloak, an expired one-time passcode remains valid twice as long as intended when using FreeOTP, giving attackers a larger time window to compromise accounts.

CVE-2024-7318
07.06.2026
CVE
OS & platform Medium

Keycloak accidentally stores sensitive data like passwords in bytecode during the build process, making this information accessible at runtime and potentially exposing confidential data.

CVE-2024-10451
07.06.2026
CVE
OS & platform Medium

A vulnerability in Keycloak allows attackers to crash the server through complex regular expressions when untrusted data is processed, causing denial of service.

CVE-2024-10270
07.06.2026
CVE
OS & platform Low

A vulnerability in Keycloak allows privileged users to read sensitive information from Vault files outside the intended context. Attackers need existing high-level access rights to the Keycloak server.

CVE-2024-10492
07.06.2026
CVE
OS & platform Medium

Keycloak version 26 and earlier can be subjected to denial-of-service attacks through manipulated proxy headers that cause the system to perform costly DNS operations, potentially blocking the service.

CVE-2024-9666
07.06.2026
CVE
OS & platform High

A vulnerability in Keycloak allows attackers on the local network to impersonate any user or client when mTLS authentication is used through a reverse proxy without pass-through TLS termination.

CVE-2024-10039
07.06.2026
CVE
OS & platform Medium

A vulnerability in Keycloak allows administrators with realm settings permissions to crash the service by inserting newlines into security headers, preventing users from accessing applications that rely on Keycloak for authentication.

CVE-2024-11734
07.06.2026
CVE
OS & platform Medium

Keycloak administrators can access confidential server environment variables and system properties by using special placeholders in configurable URLs, potentially exposing sensitive information.

CVE-2024-11736
07.06.2026
CVE
OS & platform Medium

In Keycloak, a configuration option for encrypted communication between servers doesn't work properly, causing data transmission to occur unencrypted instead of being secured as intended.

CVE-2024-10973
07.06.2026
CVE
OS & platform Medium

Keycloak fails to properly verify Active Directory account status after password resets, potentially allowing users with expired or disabled accounts to still authenticate successfully.

CVE-2025-0604
07.06.2026
CVE
OS & platform Medium

Keycloak incorrectly assigns users to organizations based only on email or username patterns. This can allow attackers to impersonate organization members when self-registration is enabled.

CVE-2025-1391
07.06.2026
CVE
OS & platform High

Keycloak incorrectly skips certificate verification when a specific verification policy is set to 'ALL', potentially allowing insecure connections to be established.

CVE-2025-3501
07.06.2026
CVE
OS & platform Medium

A vulnerability in Keycloak allows users to bypass required security measures such as setting up two-factor authentication.

CVE-2025-3910
07.06.2026
CVE
OS & platform Medium

In Keycloak, attackers can change their email address to a victim's during first login via Identity Provider, causing a verification email to be sent to the victim that grants account access if clicked.

CVE-2025-7365
07.06.2026
CVE
OS & platform Medium

A vulnerability in Keycloak allows administrators with limited privileges to grant themselves higher permissions, thereby gaining full access to system configuration and user data.

CVE-2025-7784
07.06.2026
CVE
OS & platform Medium

Keycloak users can send unwanted emails through the server by using special characters during email registration, which could serve as a starting point for further attacks.

CVE-2025-8419
07.06.2026
CVE
OS & platform Medium

A vulnerability in Keycloak's user console allows attackers to inject fake error messages through URL parameters that are then displayed in the trusted user interface, enabling phishing attacks to deceive users.

CVE-2025-10044
07.06.2026
CVE
OS & platform Medium

A vulnerability in Keycloak allows attackers to inject malicious code into realm import documents by exploiting the placeholder substitution feature. This can lead to unintended consequences within the Keycloak environment.

CVE-2025-9162
07.06.2026
CVE
OS & platform High

Keycloak servers can be overwhelmed by repeated TLS connection requests from attackers due to a Java default setting that allows harmful renegotiations. This can crash the service without attackers needing to authenticate themselves.

CVE-2025-11419
07.06.2026
CVE
OS & platform Low

A vulnerability in Keycloak allows attackers to access the admin area through manipulated paths, even when it should be protected by a proxy configuration.

CVE-2025-10939
07.06.2026
CVE
OS & platform Medium

Keycloak server in debug mode binds the debug port to all network interfaces, allowing attackers on the local network to achieve remote code execution.

CVE-2025-11538
07.06.2026
CVE
OS & platform Medium

A vulnerability in Keycloak's LDAP user federation allows authenticated administrators to trigger unsafe Java object deserialization through malicious LDAP server configurations, potentially leading to code execution.

CVE-2025-13467
07.06.2026
CVE
OS & platform High

A security flaw in Keycloak allows attackers to impersonate arbitrary users by sending manipulated SAML messages with encrypted assertions, leading to unauthorized access and potential data exposure.

CVE-2026-2092
07.06.2026
REL
OS & platform frisch

Release 2026-06-04

26.6.3
04.06.2026
REL
OS & platform bewährt

Release 2026-05-19

26.6.2
19.05.2026
REL
OS & platform bewährt

Release 2026-04-15

26.6.1
15.04.2026
EOL
OS & platform

Current / stable

26.6
08.04.2026
REL
OS & platform bewährt

Release 2026-04-08

26.6.0
08.04.2026
REL
OS & platform bewährt

Release 2026-04-02

26.5.7
02.04.2026
REL
OS & platform bewährt

Release 2026-03-19

26.5.6
19.03.2026
REL
OS & platform bewährt

Release 2026-03-05

26.5.5
05.03.2026
REL
OS & platform bewährt

Release 2026-02-20

26.5.4
20.02.2026
REL
OS & platform bewährt

Release 2026-02-10

26.5.3
10.02.2026
REL
OS & platform bewährt

Release 2026-01-23

26.5.2
23.01.2026
REL
OS & platform bewährt

Release 2026-01-14

26.5.1
14.01.2026
EOL
OS & platform

EOL 2026-04-08

26.5
06.01.2026
REL
OS & platform bewährt

Release 2026-01-06

26.5.0
06.01.2026
REL
OS & platform bewährt

Release 2025-12-01

26.4.7
01.12.2025
REL
OS & platform bewährt

Release 2025-11-25

26.4.6
25.11.2025
REL
OS & platform bewährt

Release 2025-11-12

26.4.5
12.11.2025
REL
OS & platform bewährt

Release 2025-11-07

26.4.4
07.11.2025
REL
OS & platform bewährt

Release 2025-10-23

26.4.2
23.10.2025
REL
OS & platform bewährt

Release 2025-10-16

26.4.1
16.10.2025
EOL
OS & platform

EOL 2026-01-06

26.4
30.09.2025
REL
OS & platform bewährt

Release 2025-09-30

26.4.0
30.09.2025
REL
OS & platform bewährt

Release 2025-09-25

26.3.5
25.09.2025
REL
OS & platform bewährt

Release 2025-09-12

26.3.4
12.09.2025
REL
OS & platform bewährt

Release 2025-08-20

26.3.3
20.08.2025
REL
OS & platform bewährt

Release 2025-07-24

26.3.2
24.07.2025
REL
OS & platform bewährt

Release 2025-07-09

26.3.1
09.07.2025
EOL
OS & platform

EOL 2025-09-30

26.3
02.07.2025
REL
OS & platform bewährt

Release 2025-07-02

26.3.0
02.07.2025
REL
OS & platform bewährt

Release 2025-05-28

26.2.5
28.05.2025
REL
OS & platform bewährt

Release 2025-05-08

26.2.4
08.05.2025
REL
OS & platform bewährt

Release 2025-05-05

26.2.3
05.05.2025
REL
OS & platform bewährt

Release 2025-04-30

26.2.2
30.04.2025
EOL
OS & platform

EOL 2025-07-02

26.2
11.04.2025
EOL
OS & platform

EOL 2025-04-11

26.1
15.01.2025
EOL
OS & platform

EOL 2025-01-15

26.0
04.10.2024
EOL
OS & platform

EOL 2024-10-04

25.0
10.06.2024
EOL
OS & platform

EOL 2024-06-10

24.0
04.03.2024
EOL
OS & platform

EOL 2024-03-04

23.0
23.11.2023
EOL
OS & platform

EOL 2023-11-23

22.0
11.07.2023
EOL
OS & platform

EOL 2023-07-11

21.1
19.04.2023
EOL
OS & platform

EOL 2023-04-19

21.0
23.02.2023
EOL
OS & platform

EOL 2023-02-23

20.0
01.11.2022
REL
OS & platform bewährt

Release 2022-09-27

nightly
27.09.2022
EOL
OS & platform

EOL 2022-11-01

19.0
27.07.2022
EOL
OS & platform

EOL 2022-07-27

18.0
20.04.2022
EOL
OS & platform

EOL 2022-04-20

17.0
11.02.2022
EOL
OS & platform

EOL 2022-03-11

16.1
20.12.2021
EOL
OS & platform

EOL 2021-12-20

16.0
17.12.2021
EOL
OS & platform

EOL 2021-12-17

15.1
10.12.2021
EOL
OS & platform

EOL 2021-12-10

15.0
30.07.2021
EOL
OS & platform

EOL 2021-07-15

14.0
18.06.2021
EOL
OS & platform

EOL 2021-06-18

13.0
06.05.2021
EOL
OS & platform

EOL 2021-05-06

12.0
16.12.2020
EOL
OS & platform

EOL 2020-12-16

11.0
22.07.2020
EOL
OS & platform

EOL 2020-07-22

10.0
29.04.2020