Catalog / Keycloak

Keycloak security advisories

All 82 advisories Keycloak has published with an identifier, newest first. Severity is the one its publisher assigned, and the fix is the release the publisher named. Nothing on this page is our judgement.

Advisories
8282 carry a CVE
high
28
medium
40
low
14
Fix in the archive
26of 82 matched to a release
Oldest
20 Dec 20214.7 years ago

56 of these point at a version older than anything the archive holds, so there is no release page to link. That is a gap in what was collected, not evidence that the fix does not exist. This page is a copy of what the publisher published, kept for reference. The authoritative source for a security question is the publisher, and an advisory missing from here is not evidence that none exists. What this page does and does not tell you sets out the limits in full.

Newest first

Every product
CVE-2026-15573high

Keycloak-services: keycloak-services: authorization bypass via unnormalized uri matching in pathmatcher

GHSA-2888-g6qc-w4mjFixed in 26.7.1
CVE-2026-15572high

Keycloak-services: keycloak-services: dcr protocol mapper type-swap policy bypass allows privilege escalation

GHSA-95rm-h7g9-rhcfFixed in 26.7.1
CVE-2026-16100medium

Keycloak-services: keycloak-services: unbounded metric cardinality in user event metrics via request-controlled error text

GHSA-3692-rrj9-24qwFixed in 26.7.1
CVE-2026-16442high

Keycloak-services: keycloak-services: saml idp-initiated broker login bypasses link-only restriction

GHSA-fgq2-hxm5-8xg2Fixed in 26.7.1
CVE-2026-16443high

Keycloak-services: keycloak-services: saml broker metadata import disables response signature validation

GHSA-f8m4-v488-rmrmFixed in 26.7.1
CVE-2026-16071medium

Keycloak-services: keycloak-services: ldap entry-dn user search bypasses configured users dn boundary

GHSA-hmr6-pxx9-552pFixed in 26.7.1
CVE-2026-16102high

Keycloak-services: keycloak-services: default dcr policy allows role forgery via user property mappers

GHSA-95cx-vmr5-3cmrFixed in 26.7.1
CVE-2026-9705medium

Attacker can re-enable and take over disabled clients via registration access token

GHSA-r7rc-c989-86g6Fixed in 26.6.4
CVE-2026-2092high

Keycloak: Unauthorized access via improper validation of encrypted SAML assertions

GHSA-794g-x443-36f7Fixed in 26.2.14, not held here
CVE-2025-13467medium

Deserialization of Untrusted Data in LDAP User Federation

GHSA-4hx9-48xh-5mxrFixed in 26.2.11, not held here
CVE-2025-11419high

Keycloak TLS Client-Initiated Renegotiation Denial of Service

GHSA-q8hq-4h99-fj7xFixed in 26.0.16, not held here
CVE-2025-10044medium

Keycloak error_description injection on error pages that can trigger phishing attacks

GHSA-27gc-wj6x-9w55Fixed in 26.2.9, not held here
CVE-2025-9162medium

Variable resolution on imports can expose environment variables

GHSA-8hxp-qmph-w5gqFixed in 26.2.9, not held here
CVE-2025-8419medium

Keycloak SMTP Inject Vulnerability

GHSA-m4j5-5x4r-2xp9Fixed in 26.2.8, not held here
CVE-2025-7365medium

Phishing attack via email verification step in first login flow

GHSA-xhpr-465j-7p9qFixed in 26.2.13, not held here
CVE-2025-7784medium

Privilege Escalation in Keycloak Admin Console (FGAPv2 Enabled)

GHSA-27gp-8389-hm4wFixed in 26.2.6, not held here
CVE-2025-0604medium

Authentication Bypass Due to Missing LDAP Bind After Password Reset in Keycloak

GHSA-2p82-5wwr-43cwFixed in 26.1.3
CVE-2025-1391medium

Improper Authorization in Keycloak Organization Mapper Allows Unauthorized Organization Claims

GHSA-gvgg-2r3r-53x7Fixed in 26.1.3
CVE-2024-10451medium

Sensitive Data Exposure in Keycloak Build Process

GHSA-v7gv-xpgf-6395Fixed in 24.0.9, not held here
CVE-2024-10270medium

Inefficient Regular Expression Complexity in org.keycloak:keycloak-services

GHSA-wq8x-cg39-8mrrFixed in 24.0.9, not held here
CVE-2024-10492low

Keycloak Path Traversal Vulnerability Due to External Control of File Name or Path

GHSA-5545-r4hg-rj4mFixed in 24.0.9, not held here
CVE-2024-9666medium

Keycloak proxy header handling Denial-of-Service (DoS) vulnerability

GHSA-jgwc-jh89-rpgqFixed in 24.0.9, not held here
CVE-2024-10039high

Keycloak mTLS Authentication Bypass via Reverse Proxy TLS Termination

GHSA-93ww-43rr-79v3Fixed in 24.0.9, not held here
CVE-2024-7341high

Session fixation in Elytron SAML adapters

GHSA-5rxp-2rhr-qwqvFixed in 22.0.12, not held here
CVE-2024-8883medium

Vulnerable Redirect URI Validation Results in Open Redirect

GHSA-w8gr-xwp4-r9f7Fixed in 22.0.13, not held here
CVE-2024-8698high

Improper Verification of SAML Responses Leading to Privilege Escalation in Keycloak

GHSA-xgfv-xpx8-qhcrFixed in 22.0.13, not held here
CVE-2024-7318medium

One Time Passcode (OTP) is valid longer than expiration timeSeverity

GHSA-xmmm-jw76-q7vgFixed in 24.0.7, not held here
CVE-2024-4629medium

Potential bypass of brute force protection

GHSA-gc7q-jgjv-vjr2Fixed in 22.0.12, not held here
CVE-2024-5967low

Leak of configured LDAP bind credentials through the Keycloak admin console

GHSA-c25h-c27q-5qpvFixed in 22.0.12, not held here
CVE-2024-1722low

DoS via account lockout

GHSA-cq42-vhv7-xr7pFixed in 24.0.0, not held here
CVE-2021-3754low

Improper input validation on Keycloak allows using email as username

GHSA-4vc8-pg5c-vg4xFixed in 24.0.1, not held here
CVE-2024-3656medium

Unguarded admin REST API endpoints allows low privilege users to use administrative functionalities

GHSA-2cww-fgmg-4jqcFixed in 24.0.5
CVE-2023-3597medium

Secondary factor bypass in step-up authentication

GHSA-4f53-xh3v-g8x4Fixed in 22.0.10, not held here
CVE-2023-6484low

Log Injection during WebAuthn authentication or registration

GHSA-j628-q885-8gr5Fixed in 22.0.9, not held here
CVE-2023-6544medium

Authorization Bypass

GHSA-46c8-635v-68r2Fixed in 22.0.10, not held here
CVE-2024-2419high

Path traversal in the redirect validation

GHSA-mrv8-pqfj-7gp5Fixed in 22.0.10, not held here
CVE-2023-6717high

XSS via assertion consumer service URL in SAML POST-binding flow

GHSA-8rmm-gm28-pj8qFixed in 22.0.10, not held here
CVE-2023-0657low

Impersonation via logout token exchange

GHSA-7fpj-9hr8-28vhFixed in 22.0.10, not held here
CVE-2023-6787medium

Session hijacking via re-authentication

GHSA-c9h6-v78w-52wjFixed in 22.0.10, not held here
CVE-2024-1132high

Path transversal in redirection validation

GHSA-72vp-xfrc-42xmFixed in 22.0.10, not held here
CVE-2024-1249high

Unvalidated cross-origin messages in checkLoginIframe leads to DDoS

GHSA-m6q9-p373-g5q8Fixed in 22.0.10, not held here
CVE-2023-6927medium

keycloak-core: open redirect via "form_post.jwt" JARM response mode

GHSA-9vm7-v8wj-3fqwFixed in 23.0.4, not held here
CVE-2023-6291high

The redirect_uri validation logic allows for bypassing explicitly allowed hosts that would otherwise be restricted

GHSA-mpwq-j3xf-7m5wFixed in 23.0.3, not held here
CVE-2023-6134medium

Reflected XSS via wildcard in OIDC redirect_uri

GHSA-cvg2-7c3j-g36jFixed in 23.0.3, not held here
CVE-2022-2232low

LDAP Injection on UsernameForm Login

GHSA-8hc5-rmgf-qx6pFixed in 23.0.1, not held here
CVE-2023-4918high

Plaintext Storage of User Password

GHSA-5q66-v53q-pm35Fixed in 22.0.3, not held here
CVE-2023-0105medium

Impersonation and lockout possible through incorrect handling of email trust

GHSA-c7xw-p58w-h6fjFixed in 22.0.1, not held here
CVE-2022-4361low

Cross-site scripting when validating URI-schemes on SAML and OIDC

GHSA-3p62-6fjh-3p5hFixed in 21.1.2, not held here
CVE-2023-2422high

Improper Client Certificate Validation for OAuth/OpenID clients

GHSA-3qh5-qqj2-c78fFixed in 21.1.2, not held here
CVE-2023-1664low

Untrusted Certificate Validation

GHSA-5cc8-pgp5-7mpmFixed in 21.1.2, not held here
CVE-2023-2585medium

Client Spoofing within the Keycloak Device Authorisation Grant

GHSA-f5h4-wmp5-xhg6Fixed in 21.1.2, not held here
CVE-2023-0264high

User impersonation via stolen UUID code

GHSA-9g98-5mj6-f9mvFixed in 21.0.1, not held here
CVE-2022-1274medium

HTML Injection in Keycloak Admin REST API

GHSA-m4fv-gm5m-4725Fixed in 20.0.5, not held here
CVE-2022-4137high

Reflected XSS on OpenID connect login service

GHSA-9hhc-pj4w-w5rvFixed in 20.0.5, not held here
CVE-2022-1438medium

XSS on impersonation under specific circumstances

GHSA-w354-2f3c-qvg9Fixed in 20.0.5, not held here
CVE-2023-0091low

Lack of validation of access token on client registrations endpoint

GHSA-v436-q368-hvggFixed in 20.0.3, not held here
CVE-2022-3782high

Path traversal via double URL encoding

GHSA-g8q8-fggx-9r3qFixed in 20.0.2, not held here
CVE-2022-3916medium

Session takeover with OIDC offline refreshtokens

GHSA-97g8-xfvw-q4hgFixed in 20.0.2, not held here
CVE-2022-0225medium

Stored XSS in groups dropdown

GHSA-755v-r4x4-qf7mFixed in 20.0.0, not held here
CVE-2022-2256medium

Stored XSS when loading default roles

GHSA-w9mf-83w3-fv49Fixed in 19.0.2, not held here
CVE-2022-2668low

SAML javascript protocol mapper: Uploading of scripts through admin console

GHSA-wf7g-7h6h-678vFixed in 19.0.2, not held here
CVE-2021-20323medium

Reflected XSS on clients-registrations endpoint

GHSA-m98g-63qj-fp8jFixed in 18.0.0, not held here
CVE-2020-10734low

OIDC Logout redirects can happen even if no id_token_hint is provided

GHSA-rvjg-gxwx-j5gfFixed in 18.0.0, not held here
CVE-2021-3827medium

ECP SAML binding bypasses authentication flows

GHSA-4pc7-vqv5-5r3vFixed in 18.0.0, not held here
CVE-2021-3424low

Keycloak is vulnerable to IDN homograph attack

GHSA-mwm4-5qwr-g9pfFixed in 18.0.0, not held here
CVE-2022-1245medium

Privilege escalation vulnerability on Token Exchange feature

GHSA-75p6-52g3-rqc8Fixed in 18.0.0, not held here
CVE-2021-4133high

Incorrect authorization allows unpriviledged users to create other users

GHSA-83x4-9cwr-5487Fixed in 16.0.0, not held here