ctipilot.ch

Keycloak Project (security advisories / release notes)

keycloak · A · active

https://www.keycloak.org/security

vendor-psirtvulnslang: enfailures: 0last fetch: 2026-07-12

CNCF/Red Hat upstream IAM — reference identity platform across EU public-sector e-government SSO. Release-notes blog + GitHub GHSA carry coordinated multi-CVE advisories. Discovered via Keycloak 26.6.3 deep dive 2026-06-07 (CVE-2026-9704 token-exchange privesc). Candidate — promote to active after 3 runs with content contribution. | 2026-06-20 full audit (v2.62): live, drill=Y. The configured /security URL is a static policy page (no dated advisories). FETCH → `feed https://www.keycloak.org/rss.xml` for release posts that carry coordinated multi-CVE advisories, then drill the release blog post / linked GHSA. fetch_method webfetch→rss. Stays candidate (needs content runs). | 2026-07-05 admiralty audit: A — first-party PSIRT for its own product (definitive source). Recommend candidate->active: live, drillable, relevant (EU public-sector SSO), recent clean fetch (2026-06-28, 0 failures). Fetch via rss.xml (the /security URL is static policy).

Cited in 8 entries

Citation cadence

Citation days per ISO week (7 weeks of coverage span, total 6).