Known Vulnerabilities for Keycloak by Redhat
Listed below are 10 of the newest known vulnerabilities associated with "Keycloak" by "Redhat".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-68971 json | Apache Airflow's asset materialization endpoint (`POST /api/v2/assets/{asset_id}/materialize`) and the XCom result check on `... | Not Provided | 2026-08-12 | 2026-08-13 |
| CVE-2026-53913 json | Improper Authentication, Missing Authentication for Critical Function, Not Failing Securely ('Failing Open') vulnerability in... | Not Provided | 2026-07-06 | 2026-07-07 |
| CVE-2026-48726 json | A bug in Apache Airflow's auth manager logout handling left previously-issued JWT tokens valid after the user clicked logout ... | Not Provided | 2026-06-01 | 2026-06-02 |
| CVE-2026-46455 json | Insufficient Session Expiration vulnerability in Apache Camel Keycloak Component. The camel-keycloak security helper Keycloa... | Not Provided | 2026-07-06 | 2026-07-06 |
| CVE-2026-46389 json | UDS Identity Config builds the Keycloak configuration image (realm, plugins, theme, truststore, JARs) consumed by UDS Core's ... | Not Provided | 2026-06-05 | 2026-06-05 |
| CVE-2026-37977 json | A flaw was found in Keycloak. A remote attacker can exploit a Cross-Origin Resource Sharing (CORS) header injection vulnerabi... | Not Provided | 2026-04-06 | 2026-06-26 |
| CVE-2026-19608 json | A flaw was found in the group policy provider of Keycloak authorization services, which is used to manage fine-grained access... | Not Provided | 2026-08-18 | 2026-08-18 |
| CVE-2026-18967 json | A flaw was found in the SAML broker component of Keycloak, an identity and access management solution. When configured as a S... | Not Provided | 2026-08-06 | 2026-08-06 |
| CVE-2026-18963 json | A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and ... | Not Provided | 2026-08-18 | 2026-08-20 |
| CVE-2026-18573 json | A flaw was found in the keycloak-services component of Keycloak, which is used for managing authentication and authorization ... | Not Provided | 2026-08-02 | 2026-08-03 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Redhat | Keycloak | 9.0.2 | |||
| Application | Redhat | Keycloak | 9.0.1 | |||
| Application | Redhat | Keycloak | 9.0.0 | |||
| Application | Redhat | Keycloak | 8.0.2 | |||
| Application | Redhat | Keycloak | 8.0.0 | |||
| Application | Redhat | Keycloak | 7.0.1 | |||
| Application | Redhat | Keycloak | 7.0.0 | |||
| Application | Redhat | Keycloak | 6.0.2 | |||
| Application | Redhat | Keycloak | 6.0.1 | |||
| Application | Redhat | Keycloak | 6.0.0 | |||
| Application | Redhat | Keycloak | 5.0.0 | |||
| Application | Redhat | Keycloak | 4.8.0 | |||
| Application | Redhat | Keycloak | 4.7.0 | |||
| Application | Redhat | Keycloak | 4.6.0 | |||
| Application | Redhat | Keycloak | 4.5.0 | |||
| Application | Redhat | Keycloak | 4.4.0 | |||
| Application | Redhat | Keycloak | 4.3.0 | |||
| Application | Redhat | Keycloak | 4.2.1 | |||
| Application | Redhat | Keycloak | 4.2.0 | |||
| Application | Redhat | Keycloak | 4.1.0 |