Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

321 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.1)0.27%—Redhat Keycloak10/7/202531/8/2026
A flaw was found in Keycloak. When an authenticated attacker attempts to merge accounts with another existing account during an identity provider (IdP) login, the attacker will subsequently be prompted to "review profile" information. This vulnerability allows the attacker to modify their email address to match that…
AnalizadaBaja (2.7)0.27%—Redhat Keycloak20/6/202517/6/2026
A vulnerability has been identified in Keycloak that could lead to unauthorized information disclosure. While it requires an already authenticated user, the /admin/serverinfo endpoint can inadvertently provide sensitive environment information.
AplazadaAlta (8.2)0.44%—WaspAIKeycloakAI9/6/202517/6/2026
Wasp (Web Application Specification) is a Rails-like framework for React, Node.js, and Prisma. Prior to version 0.16.6, Wasp authentication has a vulnerability in the OAuth authentication implementation (affecting only Keycloak with a specific config). Wasp currently lowercases OAuth user IDs before storing / fetching…
AplazadaMedia (5.5)0.17%—KeycloakAIZotregistry ZOTAI22/5/202517/6/2026
zot is ancontainer image/artifact registry based on the Open Container Initiative Distribution Specification. Prior to version 2.1.3 (corresponding to pseudoversion 1.4.4-0.20250522160828-8a99a3ed231f), when using Keycloak as an oidc provider, the clientsecret gets printed into the container stdout logs for an example…
AnalizadaMedia (5.4)0.44%—Redhat Build OF Keycloak29/4/202521/9/2026
A flaw was found in Keycloak. The org.keycloak.authorization package may be vulnerable to circumventing required actions, allowing users to circumvent requirements such as setting up two-factor authentication.
AplazadaAlta (8.2)0.46%—KeycloakAI29/4/202521/9/2026
A flaw was found in Keycloak. By setting a verification policy to 'ALL', the trust store certificate verification is skipped, which is unintended.
AplazadaMedia (4.9)0.69%—KeycloakAI25/3/202521/9/2026
A flaw was found in Keycloak. When the configuration uses JWT tokens for authentication, the tokens are cached until expiration. If a client uses JWT tokens with an excessively long expiration time, for example, 24 or 48 hours, the cache can grow indefinitely, leading to an OutOfMemoryError. This issue could result in…
AplazadaBaja (3.8)0.30%—KeycloakAI18/2/202517/6/2026
A vulnerability was found in Keycloak. This issue may allow a privileged attacker to use a malicious payload as the permission while creating items (Resource and Permissions) from the admin console, leading to a stored cross-site scripting (XSS) attack.
AplazadaMedia (5.4)0.41%—KeycloakAI17/2/202521/9/2026
A flaw was found in the Keycloak organization feature, which allows the incorrect assignment of an organization to a user if their username or email matches the organization’s domain pattern. This issue occurs at the mapper level, leading to misrepresentation in tokens. If an application relies on these claims for…
AplazadaMedia (5.4)0.59%—KeycloakAI22/1/202521/9/2026
A flaw was found in Keycloak. When an Active Directory user resets their password, the system updates it without performing an LDAP bind to validate the new credentials against AD. This vulnerability allows users whose AD accounts are expired or disabled to regain access in Keycloak, bypassing AD restrictions. The…
AplazadaMedia (4.9)0.77%—KeycloakAI14/1/202531/8/2026
A vulnerability was found in Keycloak. Admin users may have to access sensitive server environment variables and system properties through user-configurable URLs. When configuring backchannel logout URLs or admin URLs, admin users can include placeholders like ${env.VARNAME} or ${PROPNAME}. The server replaces these…
AplazadaMedia (6.5)0.95%—KeycloakAI14/1/202531/8/2026
A denial of service vulnerability was found in Keycloak that could allow an administrative user with the right to change realm settings to disrupt the service. This action is done by modifying any of the security headers and inserting newlines, which causes the Keycloak server to write to a request that has already…
AplazadaMedia (5.7)0.27%—KeycloakAI17/12/20248/8/2026
A vulnerability was found in Keycloak. The environment option `KC_CACHE_EMBEDDED_MTLS_ENABLED` does not work and the JGroups replication configuration is always used in plain text which can allow an attacker that has access to adjacent networks related to JGroups to read sensitive information.
AplazadaAlta (8.1)0.51%—Dapperduckling Keycloak Connector ServerAI26/11/202417/6/2026
@dapperduckling/keycloak-connector-server is an opinionated series of libraries for Node.js applications and frontend clients to interface with keycloak. A Reflected Cross-Site Scripting (XSS) vulnerability was discovered in the authentication flow of the application. This issue arises due to improper sanitization of…
AplazadaMedia (4.7)0.40%—Keycloak ServerAI25/11/202421/9/2026
A vulnerability was found in the Keycloak Server. The Keycloak Server is vulnerable to a denial of service (DoS) attack due to improper handling of proxy headers. When Keycloak is configured to accept incoming proxy headers, it may accept non-IP values, such as obfuscated identifiers, without proper validation. This…
AplazadaBaja (2.7)0.71%—KeycloakAI25/11/202421/9/2026
A vulnerability was found in Keycloak. A user with high privileges could read sensitive information from a Vault file that is not within the expected context. This attacker must have previous high access to the Keycloak server in order to perform resource creation, for example, an LDAP provider configuration and set…
AplazadaMedia (5.9)0.92%—KeycloakAI25/11/202421/9/2026
A flaw was found in Keycloak. This issue occurs because sensitive runtime values, such as passwords, may be captured during the Keycloak build process and embedded as default values in bytecode, leading to unintended information disclosure. In Keycloak 26, sensitive data specified directly in environment variables…
AplazadaMedia (6.5)1.2%—Keycloak-servicesAI25/11/202421/9/2026
A vulnerability was found in the Keycloak-services package. If untrusted data is passed to the SearchQueryUtils method, it could lead to a denial of service (DoS) scenario by exhausting system resources due to a Regex complexity.
AplazadaBaja (3.4)0.29%—KeycloakAI17/11/202417/6/2026
A flaw was found in Keycloak. This issue occurs due to improperly enforcing token types when validating signatures locally. This could allow an authenticated attacker to exchange a logout token for an access token and possibly gain access to data outside of enforced permissions.
AplazadaAlta (7.5)0.65%—KeycloakAI14/11/202417/6/2026
A flaw was found in the Keycloak package. This flaw allows an attacker to utilize an LDAP injection to bypass the username lookup or potentially perform other malicious actions.
ModificadaAlta (7.3)0.68%—Redhat Build OF KeycloakRedhat Jboss Enterprise Application Platform22/10/202419/8/2026
A vulnerability was found in Wildfly, where a user may perform Cross-site scripting in the Wildfly deployment system. This flaw allows an attacker or insider to execute a deployment with a malicious payload, which could trigger undesired behavior against the server.
AplazadaAlta (8.1)2.9%💥 ExploitKeycloakAI9/10/202417/6/2026
A flaw was found in Keycloak. Certain endpoints in Keycloak's admin REST API allow low-privilege users to access administrative functionalities. This flaw allows users to perform actions reserved for administrators, potentially leading to data breaches or system compromise.
ModificadaMedia (6.1)2.1%💥 ExploitRedhat Build OF KeycloakRedhat Openshift Container PlatformRedhat Openshift Container Platform FOR IBM ZRedhat Openshift Container Platform FOR Linuxone+219/9/20244/8/2026
A misconfiguration flaw was found in Keycloak. This issue can allow an attacker to redirect users to an arbitrary URL if a 'Valid Redirect URI' is set to http://localhost or http://127.0.0.1, enabling sensitive information such as authorization codes to be exposed to the attacker, potentially leading to session…
AplazadaAlta (7.7)2.0%💥 ExploitKeycloakAI19/9/20244/8/2026
A flaw exists in the SAML signature validation method within the Keycloak XMLSignatureUtil class. The method incorrectly determines whether a SAML signature is for the full document or only for specific assertions based on the position of the signature in the XML document, rather than the Reference element used to…
ModificadaAlta (7.5)0.74%—Redhat KeycloakRedhat Single Sign-on10/9/202417/6/2026
A denial of service vulnerability was found in keycloak where the amount of attributes per object is not limited,an attacker by sending repeated HTTP requests could cause a resource exhaustion when the application send back rows with long attribute values.
Orbitaley — Vulnerabilidades