Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

320 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (7.5)0.52%—KeycloakAI16/9/202616/9/2026
A flaw was found in the SAML Redirect Binding implementation of Keycloak, an open-source identity and access management solution. The issue occurs because the custom DEFLATE compression and decompression helpers fail to release native zlib memory after use. An unauthenticated attacker can exploit this by sending…
Pendiente de análisisAlta (8.1)0.85%—KeycloakAI16/9/202618/9/2026
Keycloak provides a policy enforcer to protect applications by matching incoming web requests against defined security policies. A flaw was found where the enforcer fails to correctly normalize web addresses that contain special encoded characters, such as those representing semicolons or directory traversal segments.…
Pendiente de análisisMedia (4.3)0.33%—Jenkins Keycloak Authentication PluginAI16/9/202618/9/2026
Jenkins Keycloak Authentication Plugin 2.4.1 and earlier does not restrict the redirect URL after login, allowing attackers to perform phishing attacks.
AnalizadaCrítica (9.8)0.98%—Apache-airflow-providers-keycloak16/9/202618/9/2026
Apache Airflow Keycloak provider: the unauthenticated token endpoint accepts a client-credentials grant for any confidential client registered in the Keycloak realm, not only the client configured for Airflow. No allowlist restricts which client ids may authenticate, so the credentials of an unrelated application that…
AnalizadaCrítica (9.1)0.81%—Apache-airflow-providers-keycloak16/9/202618/9/2026
Apache Airflow Keycloak provider: from Airflow 3.3 the Keycloak auth manager takes a user's identity from the signed Airflow session token but takes the Keycloak access and refresh tokens used for every authorization decision from separate, unauthenticated cookies, and never checks that the two describe the same…
Pendiente de análisisMedia (6.4)0.27%—KeycloakAI16/9/202617/9/2026
A flaw was found in the first broker login flow of Keycloak. When a user confirms an account-linking request from a different browser, a temporary proof is created to validate the link. However, this proof is not properly cleared after the link is established or when the user later manually removes the link. An…
Pendiente de análisisMedia (4.9)0.41%—KeycloakAI11/9/202616/9/2026
A flaw was found in the Dynamic Client Registration service of Keycloak, an open-source identity and access management solution. The issue occurs when a user with the view-clients role accesses the client registration endpoint to retrieve client details. Due to a failure to mask sensitive information, the service…
Pendiente de análisisMedia (6.5)0.35%—KeycloakAI10/9/202610/9/2026
A flaw was found in the Device Authorization Grant flow of Keycloak, an identity and access management solution. The issue occurs because the token redemption process fails to check if a user account is currently locked due to brute-force protection. If an attacker has an active session for a locked account, they can…
Pendiente de análisisMedia (4.9)0.48%—Redhat Build OF KeycloakAIRedhat KeycloakAI9/9/202616/9/2026
A flaw was found in the key provider component of the keycloak-services library, which is the core engine for the Red Hat Build of Keycloak. The issue occurs because a previous fix for path probing was incomplete, allowing a realm administrator to still submit arbitrary filesystem paths as keystore parameters. This…
AplazadaCrítica (9.9)0.55%—Eclipse AeriosAIKeycloakAIPostgresqlAIOpenldapAI8/9/20269/9/2026
In the current development version of Eclipse aeriOS, for which no official release has yet been published, the Identity Manager (IdM) deployment included insecure default configurations and credentials for security-sensitive services. The Helm chart exposed the Keycloak service and its PostgreSQL backing database…
Pendiente de análisisMedia (6.4)0.28%—KeycloakAI2/9/20263/9/2026
A flaw was found in the first-broker-login flow of the Keycloak identity management service. When a user links a social identity provider account to their local account, the verification proof generated is not strictly bound to the specific upstream identity being verified. This allows an attacker with a different…
Pendiente de análisisAlta (8.6)0.32%—Pac4j-oidcAIKeycloakAI29/8/202610/9/2026
pac4j-oidc before 6.5.6 fails to verify access token signatures, issuers, audiences, or expiry when extracting Keycloak realm and client roles. Attackers can forge access tokens with administrative roles paired with valid ID tokens to bypass authorization checks in applications relying on pac4j role validation.
Pendiente de análisisMedia (5.9)0.34%—Redhat KeycloakAI25/8/202628/9/2026
A flaw was found in the JWT Bearer authorization grant implementation within the keycloak-services component of Red Hat Build of Keycloak. This component handles various OAuth2 and OpenID Connect grant types used for issuing access tokens. The issue occurs because the JWT Bearer grant fails to check if a client…
AplazadaCrítica (10)0.41%—Miniorange Oauth ClientAIMiniorange Oauth Single Sign ON Oidc SSOAIMiniorange Login With Keycloak Oauth Single Sign ON SSOAIMiniorange Single Sign ON FOR Educational InstitutesAI24/8/20268/9/2026
Joomla Extension - miniorange.com - Arbitrary account takeover in miniOrange OAuth Client < 3.2.0, OAuth Single Sign-On – OIDC SSO < 1.2.2, Login with Keycloak OAuth Single Sign-On (SSO) < 1.2.2, Single Sign-On for Educational Institutes < 1.2.2 - The manipulation of a cookie value allows actors to login as arbitrary…
AplazadaMedia (5.3)0.15%—HCL Hive Keycloak IAMAI24/8/202629/9/2026
HCL Hive Keycloak IAM Instance is affected by insufficient granularity of access control which could allow an attacker unauthorized access to resources.
Pendiente de análisisAlta (7.3)0.43%—KeycloakAI18/8/202620/8/2026
A flaw was found in the legacy client-initiated account-linking endpoint of Keycloak, a widely used open-source identity and access management solution. The mechanism used to protect the account-linking process from unauthorized requests relies on a hash that can be predicted by a malicious OIDC client. By tricking a…
Pendiente de análisisCrítica (9.1)3.2%💥 ExploitRedhat KeycloakAIRedhat Build OF KeycloakAI18/8/20268/9/2026
A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. The issue allows an unauthenticated attacker to force the password reset process for any user without needing to click the required email…
Pendiente de análisisMedia (5.3)0.27%—KeycloakAI18/8/202618/8/2026
A flaw was found in the group policy provider of Keycloak authorization services, which is used to manage fine-grained access control to resources. The issue occurs when the system evaluates group-based policies using tokens that only contain group names rather than full paths. If two groups in different parts of the…
AnalizadaAlta (8.1)0.23%—Redhat Build OF KeycloakRedhat Jboss Enterprise Application Platform Expansion Pack6/8/202610/8/2026
A flaw was found in the SAML broker component of Keycloak, an identity and access management solution. When configured as a SAML broker using the IdP-Initiated flow, Keycloak fails to enforce the OneTimeUse condition in SAML assertions. This allows an attacker who captures a valid, unused assertion to replay it…
AnalizadaCrítica (9.8)0.31%—Redhat Build OF Keycloak5/8/202610/8/2026
A flaw was found in the SAML broker component of Keycloak, which is used to manage identity federation and user authentication. The issue occurs because the IdP-initiated Single Sign-On endpoint fails to check if a provider is restricted to account linking only. This allows an attacker with control over a linked…
AnalizadaAlta (8.8)0.65%—Redhat Build OF Keycloak5/8/202610/8/2026
A flaw was found in Keycloak's Dynamic Client Registration (DCR) security policy management. The "Allowed Protocol Mapper Types" policy, which restricts which types of data mappers a client can use, fails to re-validate the mapper type during a client update if the mapper's configuration remains unchanged. An attacker…
ModificadaAlta (8.1)0.46%—Redhat Build OF KeycloakRedhat Data GridRedhat Jboss Enterprise Application Platform Expansion PackRedhat Single Sign-on5/8/202631/8/2026
A flaw was found in the Dynamic Client Registration (DCR) component of Keycloak, an identity and access management solution. The default DCR policy fails to properly validate the claim path for User Property mappers, allowing them to write values to sensitive internal claim locations. An attacker with a standard user…
ModificadaMedia (6.5)0.55%—Redhat Build OF Keycloak5/8/202631/8/2026
A flaw was found in the user-event metrics recording of Keycloak. When metrics are enabled, the system records raw error messages from failed account operations as Prometheus metric labels. Because these error messages can include user-supplied input like nonexistent client IDs, an authenticated user can create a…
ModificadaMedia (5.4)0.32%—Redhat Build OF Keycloak5/8/202631/8/2026
A flaw was found in the LDAP storage provider of Keycloak, which is used to federate user identities from external directories. The issue occurs when a delegated administrator performs a search using a specific LDAP entry Distinguished Name (DN). Due to missing validation, the system allows lookups for users located…
ModificadaAlta (8.1)0.46%—Redhat Build OF KeycloakRedhat Data GridRedhat Jboss Enterprise Application Platform Expansion PackRedhat Single Sign-on5/8/202631/8/2026
A flaw was found in Keycloak's Authorization Services. The component responsible for matching request paths to security policies (PathMatcher) does not properly normalize URIs before comparison. By adding extra characters like a trailing slash or matrix parameters to a URL, an attacker can trick the system into…
Orbitaley — Vulnerabilidades