Keycloak Project (security advisories / release notes)
keycloak · A · active
https://www.keycloak.org/security
CNCF/Red Hat upstream IAM — reference identity platform across EU public-sector e-government SSO. Release-notes blog + GitHub GHSA carry coordinated multi-CVE advisories. Discovered via Keycloak 26.6.3 deep dive 2026-06-07 (CVE-2026-9704 token-exchange privesc). Candidate — promote to active after 3 runs with content contribution. | 2026-06-20 full audit (v2.62): live, drill=Y. The configured /security URL is a static policy page (no dated advisories). FETCH → `feed https://www.keycloak.org/rss.xml` for release posts that carry coordinated multi-CVE advisories, then drill the release blog post / linked GHSA. fetch_method webfetch→rss. Stays candidate (needs content runs). | 2026-07-05 admiralty audit: A — first-party PSIRT for its own product (definitive source). Recommend candidate->active: live, drillable, relevant (EU public-sector SSO), recent clean fetch (2026-06-28, 0 failures). Fetch via rss.xml (the /security URL is static policy).
Cited in 8 entries
Citation cadence
Citation days per ISO week (7 weeks of coverage span, total 6).
- CVE-2026-11800 (JWT algorithm-confusion) and CVE-2026-9800 (policy-enforcer authz bypass) — Keycloak identity-plane fixes2026-06-29
- Keycloak JWT algorithm confusion (CVE-2026-11800): forging federated identity in the EU public sector's dominant IdP2026-06-28
- Keycloak 26.6.3: privilege escalation via OAuth token-exchange and SSRF in the EU public sector's reference identity platform2026-06-07
- CVE-2026-10881 — Google Chrome (ANGLE graphics engine): out-of-bounds read/write enabling sandbox escape (CVSS 9.6)2026-06-07
- Looking ahead — 2026-W232026-06-01
- Keycloak 26.6.3 — 16 CVEs in the EU public sector's reference IAM, led by token-exchange privilege escalation and SSRF2026-06-01
- Keycloak 26.6.2 — 16 CVEs including OIDC session fixation (CVE-2026-7507), WebAuthn execute-actions token replay (CVE-2026-37982), introspection audience bypass (CVE-2026-37979) and cross-realm IDOR in Authorization Services (CVE-2026-4630)2026-05-21
- CVE-2026-7507 (+15) — Keycloak 26.6.2: identity-provider cluster including OIDC session fixation and cross-realm IDOR2026-05-18