Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:rpm/redhat/keycloak

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

A flaw was found in Keycloak's URL validation logic during redirect operations. By crafting a malicious request, an attacker could bypass validation to redirect users to unauthorized URLs, potentially leading to the exposure of sensitive information within the domain or facilitating further attacks. This vulnerability specifically affects Keycloak clients configured with a wildcard (*) in the "Valid Redirect URIs" field and requires user interaction to be successfully exploited. The issue stems from a discrepancy in how Keycloak and the underlying Java URI implementation handle the user-info component of a URL. If a malicious redirect URL is constructed using multiple @ characters in the user-info section, Java's URI parser fails to extract the user-info, leaving only the raw authority field. Consequently, Keycloak's validation check fails to detect the malformed user-info, falls back to a wildcard comparison, and incorrectly permits the malicious redirect.

Join the discussion

CVE-2026-37979 is an access control vulnerability in Red Hat build of Keycloak 26.4 affecting the OpenID Connect (OIDC) token introspection endpoint. It allows any confidential client with valid credentials in the realm to bypass audience restrictions and retrieve sensitive token claims intended for other resource servers. This compromises the confidentiality of lightweight access tokens. The vulnerability has a CVSS score of 6.5 (medium severity). Red Hat has released updated Keycloak 26.4.12 packages addressing this and other security issues. No explicit patch details for this CVE alone are provided, but the advisory indicates that updating to version 26.

Join the discussion

A flaw was found in org.keycloak.broker.saml. When a disabled Security Assertion Markup Language (SAML) client is configured as an Identity Provider (IdP)-initiated broker landing target, it can still complete the login process and establish a Single Sign-On (SSO) session. This allows a remote attacker to gain unauthorized access to other enabled clients without re-authentication, effectively bypassing security restrictions.

Join the discussion

A flaw was found in Keycloak. A remote attacker could bypass security controls by sending a valid SAML response from an external Identity Provider (IdP) to the Keycloak SAML endpoint for IdP-initiated broker logins. This allows the attacker to complete broker logins even when the SAML Identity Provider is disabled, leading to unauthorized authentication.

Join the discussion

A flaw was found in Keycloak. The cross-session verification proof is keyed only by (local userId, idpAlias) and is not bound to the upstream identity that was actually verified, so a second upstream account on the same IdP can consume it and get linked to the victim's local account.

Join the discussion

A flaw was found in Keycloak. The User-Managed Access (UMA) 2.0 Protection API endpoint for permission tickets fails to enforce the `uma_protection` role check. This allows any authenticated user with a token issued for a resource server client, even without the `uma_protection` role, to enumerate all permission tickets in the system. This vulnerability partial leads to information disclosure.

Join the discussion

CVE-2025-13467 is a medium severity vulnerability in Red Hat build of Keycloak 26.2 that allows an authenticated realm administrator to trigger deserialization of untrusted Java objects via a malicious LDAP server configuration. This flaw exists in the LDAP User Federation provider component. Exploitation requires high privileges (authenticated realm admin) and no user interaction. Red Hat has released updated Keycloak 26.2.11 images containing a fix for this issue. Users are advised to back up their installations and apply the update to mitigate the vulnerability.

Join the discussion

Showing 1 to 7 of 7 results

Filters:Package: pkg:rpm/redhat/keycloak
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses