Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
335 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.0% | — | Redhat Build OF Keycloak | 19/5/2026 | 6/10/2026 | A flaw was found in Keycloak. A remote, unauthenticated attacker can send a specially crafted XML input to the Security Assertion Markup Language (SAML) endpoint. This malicious input can cause high CPU usage and worker thread starvation, leading to a Denial of Service (DoS) where the server becomes unavailable. | |
| Modificada | Media (5.4) | 0.32% | — | Redhat Build OF Keycloak | 19/5/2026 | 23/7/2026 | A flaw was found in Keycloak. When both realm-level and client-level `notBefore` revocation policies are configured, Keycloak's OpenID Connect (OIDC) Introspection feature fails to properly honor the realm-level policy. This allows tokens that should have been revoked to remain active, potentially leading to… | |
| Modificada | Media (4.3) | 0.44% | — | Redhat Build OF Keycloak | 19/5/2026 | 23/7/2026 | A flaw was found in Keycloak. An authenticated user can bypass configured WebAuthn policies during credential registration by manipulating client-side JavaScript. This occurs because the server-side processAction() fails to validate that the newly created credential's parameters, such as public key algorithms, match… | |
| Aplazada | Media (5.3) | 0.33% | — | Arqit Symmetric KEY Agreement PlatformAIKeycloakAI | 13/5/2026 | 17/6/2026 | Exposed Keycloak management service in the Arqit Symmetric Key Agreement Platform enables unauthorized access to sensitive debug information such as metrics and health data. This issue affects Symmetric Key Agreement Platform: before 26.03. | |
| Modificada | Media (5.4) | 0.32% | — | Redhat Build OF Keycloak | 30/4/2026 | 26/6/2026 | When Keycloak is started with `--features-disabled=account,account-api`, the Account REST API is only partially disabled. Five endpoints under the versioned path `/account/v1alpha1` remain fully functional — including both read and write operations — because they lack the `checkAccountApiEnabled()` gate that correctly… | |
| Analizada | Media (5.4) | 0.36% | — | Apache-airflow-providers-keycloak | 18/4/2026 | 17/6/2026 | The Keycloak authentication manager in `apache-airflow-providers-keycloak` did not generate or validate the OAuth 2.0 `state` parameter on the login / login-callback flow, and did not use PKCE. An attacker with a Keycloak account in the same realm could deliver a crafted callback URL to a victim's browser and cause… | |
| Analizada | Media (4.8) | 0.38% | — | Redhat Build OF Keycloak | 14/4/2026 | 17/6/2026 | A flaw was found in Keycloak, specifically in the organization selection login page. A remote attacker with `manage-realm` or `manage-organizations` administrative privileges can exploit a Stored Cross-Site Scripting (XSS) vulnerability. This flaw occurs because the `organization.alias` is placed into an inline… | |
| Modificada | Media (5.3) | 0.27% | — | Redhat Build OF Keycloak | 6/4/2026 | 26/6/2026 | A flaw was found in Keycloak. A remote attacker can exploit a Cross-Origin Resource Sharing (CORS) header injection vulnerability in Keycloak's User-Managed Access (UMA) token endpoint. This flaw occurs because the `azp` claim from a client-supplied JSON Web Token (JWT) is used to set the `Access-Control-Allow-Origin`… | |
| Modificada | Alta (8.1) | 0.48% | — | Redhat Build OF Keycloak | 2/4/2026 | 15/7/2026 | A flaw was found in Keycloak. An authenticated user with the uma_protection role can bypass User-Managed Access (UMA) policy validation. This allows the attacker to include resource identifiers owned by other users in a policy creation request, even if the URL path specifies an attacker-owned resource. Consequently,… | |
| Analizada | Media (5.3) | 0.41% | — | Redhat Build OF Keycloak | 2/4/2026 | 17/6/2026 | A flaw was found in Keycloak. The SingleUseObjectProvider, a global key-value store, lacks proper type and namespace isolation. This vulnerability allows an attacker to delete arbitrary single-use entries, which can enable the replay of consumed action tokens, such as password reset links. This could lead to… | |
| Modificada | Alta (7.4) | 0.52% | 💥 PoC | Redhat Build OF Keycloak | 2/4/2026 | 15/7/2026 | A flaw was found in Keycloak. The SingleUseObjectProvider, a global key-value store, lacks proper type and namespace isolation. This vulnerability allows an unauthenticated attacker to forge authorization codes. Successful exploitation can lead to the creation of admin-capable access tokens, resulting in privilege… | |
| Modificada | Alta (7.3) | 0.59% | — | Redhat Build OF Keycloak | 2/4/2026 | 15/7/2026 | A flaw was found in Keycloak. This issue allows an attacker, who controls another path on the same web server, to bypass the allowed path in redirect Uniform Resource Identifiers (URIs) that use a wildcard. A successful attack may lead to the theft of an access token, resulting in information disclosure. | |
| Modificada | Alta (7.5) | 0.86% | — | Redhat Build OF Keycloak | 2/4/2026 | 6/10/2026 | A flaw was found in Keycloak. An unauthenticated attacker can exploit this vulnerability by sending a specially crafted POST request with an excessively long scope parameter to the OpenID Connect (OIDC) token endpoint. This leads to high resource consumption and prolonged processing times, ultimately resulting in a… | |
| Modificada | Media (4.3) | 0.34% | — | Redhat Build OF Keycloak | 26/3/2026 | 17/6/2026 | A flaw was found in Keycloak. The User-Managed Access (UMA) 2.0 Protection API endpoint for permission tickets fails to enforce the `uma_protection` role check. This allows any authenticated user with a token issued for a resource server client, even without the `uma_protection` role, to enumerate all permission… | |
| Modificada | Alta (7.2) | 0.53% | — | Redhat Build OF KeycloakRedhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise Application Platform Expansion PackRedhat Single Sign-on | 26/3/2026 | 17/6/2026 | A flaw was found in Keycloak. An administrator with `manage-clients` permission can exploit a misconfiguration where this permission is equivalent to `manage-permissions`. This allows the administrator to escalate privileges and gain control over roles, users, or other administrative functions within the realm. This… | |
| Modificada | Baja (3.1) | 0.33% | — | Redhat Build OF KeycloakRedhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise Application Platform Expansion PackRedhat Single Sign-on | 26/3/2026 | 26/6/2026 | A flaw was found in Keycloak. An authenticated attacker can perform Server-Side Request Forgery (SSRF) by manipulating the `client_session_host` parameter during refresh token requests. This occurs when a Keycloak client is configured to use the `backchannel.logout.url` with the `application.session.host` placeholder.… | |
| Analizada | Baja (3.7) | 0.36% | — | Redhat Build OF Keycloak | 23/3/2026 | 17/6/2026 | A flaw was found in Keycloak. A remote attacker can exploit differential error messages during the identity-first login flow when Organizations are enabled. This vulnerability allows an attacker to determine the existence of users, leading to information disclosure through user enumeration. | |
| Analizada | Media (4.3) | 0.27% | — | Redhat Build OF Keycloak | 23/3/2026 | 17/6/2026 | A flaw was found in Keycloak. An improper Access Control vulnerability in Keycloak’s User-Managed Access (UMA) resource_set endpoint allows attackers with valid credentials to bypass the allowRemoteResourceManagement=false restriction. This occurs due to incomplete enforcement of access control checks on PUT… | |
| Modificada | Media (5.8) | 0.39% | — | Redhat Build OF KeycloakRedhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise Application Platform Expansion PackRedhat Single Sign-on | 18/3/2026 | 17/6/2026 | A flaw was identified in Keycloak, an identity and access management solution, where it improperly follows HTTP redirects when processing certain client configuration requests. This behavior allows an attacker to trick the server into making unintended requests to internal or restricted resources. As a result,… | |
| Modificada | Media (5.3) | 0.83% | — | Redhat Build OF Keycloak | 18/3/2026 | 6/10/2026 | A flaw was found in Keycloak. An unauthenticated remote attacker can trigger an application level Denial of Service (DoS) by sending a highly compressed SAMLRequest through the SAML Redirect Binding. The server fails to enforce size limits during DEFLATE decompression, leading to an OutOfMemoryError (OOM) and… | |
| Analizada | Alta (8.1) | 0.72% | — | Redhat Build OF Keycloak | 18/3/2026 | 18/8/2026 | A flaw was found in Keycloak. A remote attacker could bypass security controls by sending a valid SAML response from an external Identity Provider (IdP) to the Keycloak SAML endpoint for IdP-initiated broker logins. This allows the attacker to complete broker logins even when the SAML Identity Provider is disabled,… | |
| Modificada | Alta (7.7) | 0.36% | — | Redhat Build OF Keycloak | 18/3/2026 | 6/10/2026 | A flaw was found in Keycloak. Keycloak's Security Assertion Markup Language (SAML) broker endpoint does not properly validate encrypted assertions when the overall SAML response is not signed. An attacker with a valid signed SAML assertion can exploit this by crafting a malicious SAML response. This allows the… | |
| Analizada | Baja (3.1) | 0.27% | — | Redhat Build OF Keycloak | 12/3/2026 | 18/8/2026 | A flaw was found in Keycloak. An authorization bypass vulnerability in the Keycloak Admin API allows any authenticated user, even those without administrative privileges, to enumerate the organization memberships of other users. This information disclosure occurs if the attacker knows the victim's unique identifier… | |
| Analizada | Media (4.2) | 0.32% | — | Redhat Build OF Keycloak | 11/3/2026 | 18/8/2026 | A flaw was identified in the Account REST API of Keycloak that allows a user authenticated at a lower security level to perform sensitive actions intended only for higher-assurance sessions. Specifically, an attacker who has already obtained a victim’s password can delete the victim’s registered MFA/OTP credential… | |
| Analizada | Baja (2.7) | 0.39% | — | Redhat Build OF Keycloak | 11/3/2026 | 17/6/2026 | A flaw was found in Keycloak. An authenticated user with the view-users role could exploit a vulnerability in the UserResource component. By accessing a specific administrative endpoint, this user could improperly retrieve user attributes that were configured to be hidden. This unauthorized information disclosure… |