Keycloak
6 known vulnerabilities
Top Products
It was found that keycloak before 3.4.2 final would permit misuse of a client-side /etc/hosts entry to spoof a URL in a
JBoss KeyCloak before 1.0.3.Final allows remote attackers to cause a denial of service (resource consumption) via a larg
It was found that the cookie used for CSRF prevention in Keycloak was not unique to each session. An attacker could use
It was found that Keycloak would accept a HOST header URL in the admin console and use it to determine web resource loca
The org.keycloak.services.resources.SocialResource.callback method in JBoss KeyCloak before 1.0.3.Final allows remote at
It was found that the Keycloak Node.js adapter 2.5 - 3.0 did not handle invalid tokens correctly. An attacker could use
Frequently Asked Questions
How many CVEs affect Keycloak?
Keycloak has 6 CVE records in our database, including 1 critical and 4 high severity vulnerabilities.
What are the most severe Keycloak vulnerabilities?
Keycloak has 1 critical severity (CVSS 9.0+) and 4 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for Keycloak vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Keycloak products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Keycloak Vulnerabilities
CyberStrike scans your infrastructure for Keycloak vulnerabilities and provides real-time remediation guidance.
Get Started