Skip to content

Consider path params in the unsafe path for RedirectUtils (#436)#47788

Merged
stianst merged 1 commit into
keycloak:mainfrom
rmartinc:issue-47718
Apr 7, 2026
Merged

Consider path params in the unsafe path for RedirectUtils (#436)#47788
stianst merged 1 commit into
keycloak:mainfrom
rmartinc:issue-47718

Conversation

@rmartinc

@rmartinc rmartinc commented Apr 7, 2026

Copy link
Copy Markdown
Contributor

Closes CVE-2026-3872
Closes #47718

Port to main.

@rmartinc rmartinc requested a review from a team as a code owner April 7, 2026 06:49
@stianst stianst enabled auto-merge (squash) April 7, 2026 06:56
@stianst stianst merged commit 103433e into keycloak:main Apr 7, 2026
84 checks passed
@meeranh

meeranh commented Apr 8, 2026

Copy link
Copy Markdown

Hey @rmartinc, I'm the original reporter of this vulnerability via YesWeHack. Could you add me as reporter on the GitHub Security Advisory (GHSA-cjm2-j6cm-6p6m)? Red Hat has already acknowledged me on the CVE page in the acknowledgements section. My GitHub username is @meeranh.

Thanks!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

CVE-2026-3872 Redirect URI validation bypass via ..;/ path traversal in OIDC auth endpoint

3 participants