Keycloak Project (security advisories / release notes)
keycloak · A · active
https://www.keycloak.org/security
CNCF/Red Hat upstream IAM, reference identity platform across EU public-sector e-government SSO. Release-notes blog + GitHub GHSA carry coordinated multi-CVE advisories. Discovered via Keycloak 26.6.3 deep dive 2026-06-07 (CVE-2026-9704 token-exchange privesc). Candidate; promote to active after 3 runs with content contribution. | 2026-06-20 full audit (v2.62): live, drill=Y. The configured /security URL is a static policy page (no dated advisories). FETCH → `feed https://www.keycloak.org/rss.xml` for release posts that carry coordinated multi-CVE advisories, then drill the release blog post / linked GHSA. fetch_method webfetch→rss. Stays candidate (needs content runs). | 2026-07-05 admiralty audit: A, first-party PSIRT for its own product (definitive source). Recommend candidate->active: live, drillable, relevant (EU public-sector SSO), recent clean fetch (2026-06-28, 0 failures). Fetch via rss.xml (the /security URL is static policy).
Cited in 4 entries
Citation cadence
Citation days per ISO week (6 weeks of coverage span, total 3).
- Keycloak JWT algorithm confusion (CVE-2026-11800): forging federated identity in the EU public sector's dominant IdP2026-06-28
- Keycloak 26.6.3: privilege escalation via OAuth token-exchange and SSRF in the EU public sector's reference identity platform2026-06-07
- CVE-2026-10881, Google Chrome (ANGLE graphics engine): out-of-bounds read/write enabling sandbox escape (CVSS 9.6)2026-06-07
- Keycloak 26.6.2, 16 CVEs including OIDC session fixation (CVE-2026-7507), WebAuthn execute-actions token replay (CVE-2026-37982), introspection audience bypass (CVE-2026-37979) and cross-realm IDOR in Authorization Services (CVE-2026-4630)2026-05-21