CVE Tools

Keycloak

3 CVEs tracked since 2017. Since Oct 2017, none of them reached CISA KEV.

Keycloak CVEs per month

Oct 2017 to Oct 2017. Point at a month, or focus the strip and use the arrow keys.
Keycloak CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2017-1030

Products

The products that kept showing up in Keycloak's monthly top three, with their CVEs summed over those months.

  1. Keycloak31 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Keycloak.

  1. CVE-2026-90997Keycloak-services: keycloak: replay protection bypass leads to unauthorized access via database driver semantics mismatch7.4
  2. CVE-2026-1609Org.keycloak/keycloak-quarkus-server: keycloak: unauthorized access via jwt authorization grant with disabled users8.1
  3. CVE-2025-12150Org.keycloak/keycloak-services: webauthn attestation statement verification bypass3.1
  4. CVE-2025-13467Org.keycloak.storage.ldap: keycloak: deserialization of untrusted data in ldap user federation5.5
  5. CVE-2025-11538Keycloak-server: debug default bind address6.8
  6. CVE-2025-12390Org.keycloak.protocol.oidc.endpoints.logoutendpoint: offline session takeover due to reused authentication session id6.0
  7. CVE-2025-10939Org.keycloak/keycloak-quarkus-server: unable to restrict access to the admin console3.7
  8. CVE-2025-12110Keycloak: org.keycloak:keycloak-services: user can refresh offline session even after client's offline_access scope was removed5.4
  9. CVE-2025-11429Keycloak-server: too long and not settings compliant session5.4
  10. CVE-2025-10044Keycloak: keycloak error_description injection on error pages4.3
  11. CVE-2025-9162Org.keycloak/keycloak-model-storage-service: variable injection into environment variables4.9
  12. CVE-2025-8419Org.keycloak/keycloak-services: keycloak smtp inject vulnerability5.3
  13. CVE-2022-4361Keycloak, an open-source identity and access management solution, has a cross-site scripting (XSS) vulnerability in the SAML or OIDC providers. The vulnerability can allow an attacker to execute ma...10.0
  14. CVE-2020-10686A flaw was found in Keycloak version 8.0.2 and 9.0.0, and was fixed in Keycloak version 9.0.1, where a malicious user registers as oneself. The attacker could then use the remove devices form to po...4.1
  15. CVE-2019-14820It was found that keycloak before version 8.0.0 exposes internal adapter endpoints in org.keycloak.constants.AdapterConstants, which can be invoked via a specially-crafted URL. This vulnerability c...4.3

The record

Peak rank
#115 in Oct 2017
Busiest month shown
Oct 2017, 3 CVEs
Months with a KEV entry
0 since Oct 2017
Monthly snapshots
1 since 2017
Keycloak's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store