redhat
4 records · 0 with a public proof-of-concept
Disclosed vulnerabilities where the NVD names redhat as an affected vendor, highest CVSS first.
- HIGH 8.1CVE-2026-15573
A flaw was found in Keycloak's Authorization Services. The component responsible for matching request paths to security policies (PathMatcher) does not properly normalize URIs before comparison. By adding extra characters like a trailing slash or matrix parame…
build of keycloak · data grid · jboss enterprise application platform expansion pack · single sign-on
- HIGH 7.4CVE-2026-16443
A flaw was found in the SAML metadata import functionality of the keycloak-services component, which is the core engine for identity brokering in Red Hat Build of Keycloak. When importing identity provider metadata that lacks specific usage attributes for keys…
build of keycloak
- MEDIUM 6.5CVE-2026-16100
A flaw was found in the user-event metrics recording of Keycloak. When metrics are enabled, the system records raw error messages from failed account operations as Prometheus metric labels. Because these error messages can include user-supplied input like none…
build of keycloak
- MEDIUM 5.4CVE-2026-16071
A flaw was found in the LDAP storage provider of Keycloak, which is used to federate user identities from external directories. The issue occurs when a delegated administrator performs a search using a specific LDAP entry Distinguished Name (DN). Due to missin…
build of keycloak