VendorsRed Hatkeycloakall versions
Vulnerabilities

Red Hat Keycloak

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

99CVEs
CVE-2021-3754
A flaw was found in keycloak where an attacker is able to register himself with the username same as the email ID of any existing user. This may cause trouble in getting password recovery email in case the user forgets the password.
Published 2022-08-26 · Modified
5.3EPSS 0.021
CVE-2024-1722
Keycloak-core: dos via account lockout
Published 2024-02-27 · Analyzed
5.3EPSS 0.008
CVE-2025-8419
Org.keycloak/keycloak-services: keycloak smtp inject vulnerability
Published 2025-08-06 · Modified
5.3EPSS 0.004
CVE-2023-0264
A flaw was found in Keycloaks OpenID Connect user authentication, which may incorrectly authenticate requests. An authenticated attacker who could obtain information from a user request within the same realm could use that data to impersonate the victim and generate new session tokens. This issue could impact confidentiality, integrity, and availability.
Published 2023-08-04 · Modified
5.0EPSS 0.013
CVE-2020-1694
A flaw was found in all versions of Keycloak before 10.0.0, where the NodeJS adapter did not support the verify-token-audience. This flaw results in some users having access to sensitive information outside of their permissions.
Published 2020-09-16 · Modified
4.9EPSS 0.016
CVE-2018-10912
keycloak before version 4.0.0.final is vulnerable to a infinite loop in session replacement. A Keycloak cluster with multiple nodes could mishandle an expired session replacement and lead to an infinite loop. A malicious authenticated user could use this flaw to achieve Denial of Service on the server.
Published 2018-07-23 · Modified
4.9EPSS 0.013
CVE-2020-14302
A flaw was found in Keycloak before 13.0.0 where an external identity provider, after successful authentication, redirects to a Keycloak endpoint that accepts multiple invocations with the use of the same "state" parameter. This flaw allows a malicious user to perform replay attacks.
Published 2020-12-15 · Modified
4.9EPSS 0.010
CVE-2020-27826
A flaw was found in Keycloak before version 12.0.0 where it is possible to update the user's metadata attributes using Account REST API. This flaw allows an attacker to change its own NameID attribute to impersonate the admin user for any particular application.
Published 2021-05-28 · Modified
4.9EPSS 0.006
CVE-2026-0871
Org.keycloak/keycloak-services: keycloak: unauthorized modification of unmanaged user attributes by administrators
Published 2026-02-27 · Analyzed
4.9EPSS 0.003
CVE-2020-10776
A flaw was found in Keycloak before version 12.0.0, where it is possible to add unsafe schemes for the redirect_uri parameter. This flaw allows an attacker to perform a Cross-site scripting attack.
Published 2020-11-17 · Modified
4.8EPSS 0.008
CVE-2021-3856
ClassLoaderTheme and ClasspathThemeResourceProviderFactory allows reading any file available as a resource to the classloader. By sending requests for theme resources with a relative path from an external HTTP client, the client will receive the content of random files if available.
Published 2022-08-26 · Modified
4.3EPSS 0.011
CVE-2020-1724
A flaw was found in Keycloak in versions before 9.0.2. This flaw allows a malicious user that is currently logged in, to see the personal information of a previously logged out user in the account manager section.
Published 2020-05-11 · Modified
4.3EPSS 0.008
CVE-2019-14820
It was found that keycloak before version 8.0.0 exposes internal adapter endpoints in org.keycloak.constants.AdapterConstants, which can be invoked via a specially-crafted URL. This vulnerability could allow an attacker to access unauthorized information.
Published 2020-01-08 · Modified
4.3EPSS 0.007
CVE-2014-3655
JBoss KeyCloak is vulnerable to soft token deletion via CSRF
Published 2019-11-13 · Modified
4.3EPSS 0.005
CVE-2020-1717
A flaw was found in Keycloak 7.0.1. A logged in user can do an account email enumeration attack.
Published 2021-02-11 · Modified
4.0EPSS 0.008
CVE-2023-0091
A flaw was found in Keycloak, where it did not properly check client tokens for possible revocation in its client credential flow. This flaw allows an attacker to access or modify potentially sensitive information.
Published 2023-01-11 · Modified
3.8EPSS 0.005
CVE-2020-10734
A vulnerability was found in keycloak in the way that the OIDC logout endpoint does not have CSRF protection. Versions shipped with Red Hat Fuse 7, Red Hat Single Sign-on 7, and Red Hat Openshift Application Runtimes are believed to be vulnerable.
Published 2021-02-11 · Modified
3.3EPSS 0.002
CVE-2025-12150
Org.keycloak/keycloak-services: webauthn attestation statement verification bypass
Published 2026-02-27 · Analyzed
3.1EPSS 0.002
CVE-2025-5416
Keycloak-core: keycloak environment information
Published 2025-06-20 · Analyzed
2.7EPSS 0.003
← Prev3 / 3