Security: keycloak/keycloak
Security Advisories
View information about security vulnerabilities from this repository's maintainers.
-
Replay protection bypass leads to unauthorized access via database driver semantics mismatchGHSA-xpwp-2pcm-8xq3 published
Sep 16, 2026 by ahus1High -
Keycloak-services: keycloak-services: default dcr policy allows role forgery via user property mappersGHSA-95cx-vmr5-3cmr published
Aug 6, 2026 by pskopekHigh -
Keycloak-services: keycloak-services: ldap entry-dn user search bypasses configured users dn boundaryGHSA-hmr6-pxx9-552p published
Aug 6, 2026 by pskopekModerate -
Keycloak-services: keycloak-services: saml broker metadata import disables response signature validationGHSA-f8m4-v488-rmrm published
Aug 6, 2026 by pskopekHigh -
Keycloak-services: keycloak-services: saml idp-initiated broker login bypasses link-only restrictionGHSA-fgq2-hxm5-8xg2 published
Aug 6, 2026 by pskopekHigh -
Keycloak-services: keycloak-services: unbounded metric cardinality in user event metrics via request-controlled error textGHSA-3692-rrj9-24qw published
Aug 6, 2026 by pskopekModerate -
Keycloak-services: keycloak-services: dcr protocol mapper type-swap policy bypass allows privilege escalationGHSA-95rm-h7g9-rhcf published
Aug 6, 2026 by pskopekHigh -
Keycloak-services: keycloak-services: authorization bypass via unnormalized uri matching in pathmatcherGHSA-2888-g6qc-w4mj published
Aug 6, 2026 by pskopekHigh -
Authentication bypass via jwt algorithm confusionGHSA-j97h-3f8r-mrjr published
Jun 26, 2026 by pskopekHigh -
Authorization bypass via incorrect uri comparisonGHSA-f5p5-6xmx-p252 published
Jun 26, 2026 by pskopekHigh