Build of keycloak
This hub aggregates every CVE we track for Build of keycloak, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.
Operating Systemson-prem
89
CVEs tracked
0
Critical
19
High
0
In CISA KEV
Severity distribution
MEDIUM62HIGH19LOW8
Monthly trend
5
1
0
0
0
0
0
1
0
0
1
0
0
0
0
0
0
2
10
8
24
10
21
3
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Build of keycloak.
- CVE-2026-18572Keycloak-services: keycloak-services: uma claim token can override authorization time-policy evaluation attributes6.5
- CVE-2026-18571Keycloak-services: keycloak-services: fgap v2 group assignment bypass during user creation6.6
- CVE-2026-18570Keycloak-services: keycloak-services: full-scope-disabled client policy validation bypass via omitted fullscopeallowed5.4
- CVE-2026-18209Keycloak-services: keycloak-services: oidc redirect_uri fragment bypass in http parameter pollution check3.4
- CVE-2026-18206Keycloak-services: keycloak-services: client policy source-host wildcard domain matching bypass3.7
- CVE-2026-18214Keycloak-services: keycloak-services: google external access-token exchange bypasses hosted-domain restriction6.8
- CVE-2026-18203Keycloak-services: keycloak-services: group policy extendchildren matches sibling group path prefixes6.5
- CVE-2026-18211Keycloak-services: keycloak-services: secure-client-uris policy bypass via localhost-prefixed domains4.2
- CVE-2026-18208Keycloak-services: keycloak-services: inactive out-of-audience token introspection leaks signed jwt claim6.5
- CVE-2026-16105Keycloak-services: keycloak-services: missing per-role authorization on rolecontainerresource composite endpoints4.9
- CVE-2026-18215Keycloak-services: keycloak-services: microsoft external access-token exchange bypasses configured tenant6.8
- CVE-2026-18217Keycloak-services: keycloak-services: saml http-redirect binding response preserves query string leading to parameter pollution3.4
- CVE-2026-18218Keycloak-services: keycloak-services: client not-before revocation ignored when realm not-before is older but nonzero4.2
- CVE-2026-18201Keycloak-services: keycloak-services: generic identity-provider creation can bind brokers to organizations without manage-organizations5.5
- CVE-2026-16104Keycloak-services: keycloak-services: authenticator config endpoint exposes raw recaptcha secrets to view-only admins4.3
Product normalization is registry-driven with AI assist and human review. How it works