Build of Keycloak
111 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Build of Keycloak, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.
Build of Keycloak CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 1 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 1 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 1 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 2 |
| 2026-03 | 14 |
| 2026-04 | 8 |
| 2026-05 | 24 |
| 2026-06 | 11 |
| 2026-07 | 28 |
| 2026-08 | 13 |
| 2026-09 | 0 |
Severity
How the 111 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- High26
- Medium75
- Low10
Latest CVEs
The 15 most recently published vulnerabilities affecting Build of Keycloak.
- CVE-2026-18967Keycloak-services: keycloak-services: saml onetimeuse assertion replay in idp-initiated broker flow6.4
- CVE-2026-15572Keycloak-services: keycloak-services: dcr protocol mapper type-swap policy bypass allows privilege escalation8.8
- CVE-2026-16442Keycloak-services: keycloak-services: saml idp-initiated broker login bypasses link-only restriction7.4
- CVE-2026-16100Keycloak-services: keycloak-services: unbounded metric cardinality in user event metrics via request-controlled error text6.5
- CVE-2026-16071Keycloak-services: keycloak-services: ldap entry-dn user search bypasses configured users dn boundary5.4
- CVE-2026-16102Keycloak-services: keycloak-services: default dcr policy allows role forgery via user property mappers8.1
- CVE-2026-15573Keycloak-services: keycloak-services: authorization bypass via unnormalized uri matching in pathmatcher8.1
- CVE-2026-16443Keycloak-services: keycloak-services: saml broker metadata import disables response signature validation7.4
- CVE-2026-18569Keycloak-services: keycloak-services: oidc backchannel logout accepts unsigned forged logout tokens3.7
- CVE-2026-18573Keycloak-services: keycloak-services: client access-type policy condition bypass during client update6.5
- CVE-2026-18572Keycloak-services: keycloak-services: uma claim token can override authorization time-policy evaluation attributes6.5
- CVE-2026-18571Keycloak-services: keycloak-services: fgap v2 group assignment bypass during user creation6.6
- CVE-2026-18570Keycloak-services: keycloak-services: full-scope-disabled client policy validation bypass via omitted fullscopeallowed5.4
- CVE-2026-18209Keycloak-services: keycloak-services: oidc redirect_uri fragment bypass in http parameter pollution check3.4
- CVE-2026-18206Keycloak-services: keycloak-services: client policy source-host wildcard domain matching bypass3.7
Product grouping is registry-driven, with AI assist and human review. How it works