Where
-Infinity
0

Red Hat 3scaleA vulnerability was found in 3Scale when using with Keycloak 15 (or RHSSO 7.5.0) and superiors. When…

Risk 19
Severity
4
First published (updated )

redhat/keycloakKeycloak: open redirect via "form_post.jwt" jarm response mode

Risk 28
Severity
6.1
EPSS
0.12%
First published (updated )

redhat Single Sign-onKeycloak: offline session token dos

Risk 32
Severity
7.7
EPSS
0.09%
First published (updated )

Red Hat Single Sign-On2 vulnerabilities

Risk 23
First published (updated )

Keycloak: client access via device auth request spoof

Risk 61
Severity
8.1
First published (updated )

A flaw was found in keycloak-core. This flaw considers the scenario when using X509 Client Certifica…

Risk 41
Severity
6.5
First published (updated )

Red Hat Single Sign-On2 vulnerabilities

Risk 23
First published (updated )

Keycloak: client access via device auth request spoof

Risk 61
Severity
8.1
First published (updated )

A flaw was found in keycloak-core. This flaw considers the scenario when using X509 Client Certifica…

Risk 41
Severity
6.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

redhat OpenShift Container PlatformKeycloak: oauth client impersonation

Risk 50
Severity
7.1
First published (updated )

redhat/rh-sso7-keycloakKeycloak's OpenID Connect user authentication was found to incorrectly authenticate requests. An aut…

Risk 63
Severity
8.7
First published (updated )

maven/org.keycloak:keycloak-coreA flaw was found in Keycloak. This flaw allows impersonation and lockout due to the email trust not …

Risk 41
Severity
6.5
First published (updated )

redhat/eap7-undertowSSRF

Risk 89
Severity
9.8
First published (updated )

redhat Single Sign-onXSS

Risk 89
Severity
10
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

redhat/rh-sso7-keycloakKeycloak: reflected xss attack

Risk 60
Severity
8.1
First published (updated )

redhat OpenShift Container PlatformRhsso-container-image: unsecured management interface exposed to adjecent network

Risk 88
Severity
9.8
First published (updated )

redhat/rh-sso7-keycloakKeycloak: session takeover with oidc offline refreshtokens

Risk 54
Severity
6.8
First published (updated )

redhat/rh-sso7-keycloakInput Validation

Risk 27
Severity
3.8
First published (updated )

redhat/eap7-undertowUndertowInputStream.close() blocks waiting to read -1 https://issues.redhat.com/browse/UNDERTOW-204…

Risk 30
Severity
4.9
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

redhat/rh-sso7-keycloakAn issue was discovered in Keycloak that allows arbitrary Javascript to be uploaded for the SAML pro…

Risk 69
Severity
7.2
First published (updated )

redhat/rh-sso7-keycloakXSS

Risk 27
Severity
3.8
First published (updated )

redhat undertowA flaw was found in Undertow. For an AJP 400 response, EAP 7 is improperly sending two response pack…

Risk 45
Severity
7.5
First published (updated )

redhat WildflyA flaw was found in WildFly, where an attacker can see deployment names, endpoints, and any other da…

Risk 45
Severity
7.5
First published (updated )

redhat OpenShift Container PlatformXSS

Risk 49
Severity
7.6
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

redhat/eap7-undertowA flaw was found in Undertow. A potential security issue in flow control handling by the browser ove…

Risk 45
Severity
7.5
First published (updated )

Red Hat Single Sign-OnModerate: Red Hat Single Sign-On 7.5.1 security update

Risk 23
First published (updated )

Red Hat Single Sign-OnModerate: Red Hat Single Sign-On 7.4.10 on OpenJ9 for OpenShift image security update

Risk 32
First published (updated )

Red Hat Single Sign-OnModerate: Red Hat Single Sign-On 7.4.10 on OpenJDK for OpenShift image security update

Risk 32
First published (updated )

redhat/keycloakDue to improper authorization, Red Hat Single Sign-On is vulnerable to users performing actions that…

Risk 40
Severity
6.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Red Hat Single Sign-On1 vulnerability

Risk 23
First published (updated )

Invocation of an EJB is failing on the client side with the invocation-timeout being hit. Reference…

Risk 45
Severity
7.5
First published (updated )

redhat/rh-sso7-keycloakXSS

Risk 46
Severity
5.7
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203