CVE-2026-103884: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Red Hat Red Hat Build of Keycloak
A flaw was found in the X.509 client certificate authenticator of Keycloak. When CRL Distribution Point checking is enabled, the server fails to properly validate the file paths provided in a client certificate. An attacker can provide a specially crafted certificate that causes the server to attempt to read sensitive files from the local system or exhaust memory by loading extremely large files, potentially leading to information disclosure or a system crash.
AI Analysis
Technical Summary
CVE-2026-103884 describes a path traversal flaw in the X.509 client certificate authenticator component of Red Hat Build of Keycloak. When CRL Distribution Point checking is enabled, the server does not correctly validate file paths specified in client certificates. An attacker can exploit this by supplying a crafted certificate that causes the server to access arbitrary files on the local filesystem or consume excessive memory by loading large files, resulting in potential information disclosure or denial of service via system crash.
Potential Impact
The vulnerability can lead to limited confidentiality impact through information disclosure of local files and high impact on availability due to potential system crashes from memory exhaustion. There is no indication of integrity impact. The CVSS score is 6.5 (medium severity), reflecting network attack vector with high attack complexity and no privileges or user interaction required.
Mitigation Recommendations
Patch status is not yet confirmed — check the Red Hat advisory at https://access.redhat.com/security/cve/CVE-2026-103884 for current remediation guidance. Until a fix is applied, consider disabling CRL Distribution Point checking if feasible, or restrict certificate sources to trusted entities to reduce exposure.
CVE-2026-103884: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Red Hat Red Hat Build of Keycloak
Description
A flaw was found in the X.509 client certificate authenticator of Keycloak. When CRL Distribution Point checking is enabled, the server fails to properly validate the file paths provided in a client certificate. An attacker can provide a specially crafted certificate that causes the server to attempt to read sensitive files from the local system or exhaust memory by loading extremely large files, potentially leading to information disclosure or a system crash.
CVSS v3.1
Score 6.5medium
Affected software
Red Hat
Red Hat Build of Keycloak
Red Hat
Red Hat Single Sign-On 7
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-103884 describes a path traversal flaw in the X.509 client certificate authenticator component of Red Hat Build of Keycloak. When CRL Distribution Point checking is enabled, the server does not correctly validate file paths specified in client certificates. An attacker can exploit this by supplying a crafted certificate that causes the server to access arbitrary files on the local filesystem or consume excessive memory by loading large files, resulting in potential information disclosure or denial of service via system crash.
Potential Impact
The vulnerability can lead to limited confidentiality impact through information disclosure of local files and high impact on availability due to potential system crashes from memory exhaustion. There is no indication of integrity impact. The CVSS score is 6.5 (medium severity), reflecting network attack vector with high attack complexity and no privileges or user interaction required.
Mitigation Recommendations
Patch status is not yet confirmed — check the Red Hat advisory at https://access.redhat.com/security/cve/CVE-2026-103884 for current remediation guidance. Until a fix is applied, consider disabling CRL Distribution Point checking if feasible, or restrict certificate sources to trusted entities to reduce exposure.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- redhat
- Date Reserved
- 2026-10-01T13:22:41.176Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-103884","vendor":"Red Hat"}]
Threat ID: 6abe9906a43b0b3b89d6e6c0
Added to database: 10/01/2026, 17:31:50 UTC
Last enriched: 10/01/2026, 17:46:30 UTC
Last updated: 10/01/2026, 18:31:49 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.