Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-63v5-26vq-m4vm

Опубликовано: 26 янв. 2026
Источник: github
Github: Прошло ревью
CVSS3: 3.1

Описание

Keycloak's missing timestamp validation allows attackers to extend SAML response validity periods

A flaw was found in Keycloak's SAML brokering functionality. When Keycloak is configured as a client in a Security Assertion Markup Language (SAML) setup, it fails to validate the NotOnOrAfter timestamp within the SubjectConfirmationData. This allows an attacker to delay the expiration of SAML responses, potentially extending the time a response is considered valid and leading to unexpected session durations or resource consumption.

Пакеты

Наименование

org.keycloak:keycloak-services

maven
Затронутые версииВерсия исправления

<= 26.5.2

Отсутствует

EPSS

Процентиль: 15%
0.00048
Низкий

3.1 Low

CVSS3

Дефекты

CWE-112
CWE-347
CWE-613

Связанные уязвимости

CVSS3: 3.1
nvd
11 дней назад

A flaw was found in Keycloak's SAML brokering functionality. When Keycloak is configured as a client in a Security Assertion Markup Language (SAML) setup, it fails to validate the `NotOnOrAfter` timestamp within the `SubjectConfirmationData`. This allows an attacker to delay the expiration of SAML responses, potentially extending the time a response is considered valid and leading to unexpected session durations or resource consumption.

CVSS3: 3.1
debian
11 дней назад

A flaw was found in Keycloak's SAML brokering functionality. When Keyc ...

EPSS

Процентиль: 15%
0.00048
Низкий

3.1 Low

CVSS3

Дефекты

CWE-112
CWE-347
CWE-613