Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p3v8-fm5p-v84h

Опубликовано: 28 мая 2026
Источник: github
Github: Прошло ревью
CVSS3: 5.9

Описание

Keycloak has an Improper Verification of Cryptographic Signature issue

A flaw was found in Keycloak. When a JSON Web Encryption (JWE) encrypted request object is submitted, Keycloak may incorrectly process unsigned claims if the decrypted content is raw JSON, bypassing the configured signature policy. This allows a remote attacker to submit unauthorized claims, leading to a compromise of data integrity within the OpenID Connect (OIDC) authorization flow. While a redirect URI allowlist acts as a compensating control, this vulnerability violates OIDC Core and Financial-grade API (FAPI) signing requirements.

Пакеты

Наименование

org.keycloak:keycloak-services

maven
Затронутые версииВерсия исправления

<= 26.6.4

Отсутствует

EPSS

Процентиль: 2%
0.0012
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-347

Связанные уязвимости

CVSS3: 5.9
redhat
2 месяца назад

A flaw was found in Keycloak. When a JSON Web Encryption (JWE) encrypted request object is submitted, Keycloak may incorrectly process unsigned claims if the decrypted content is raw JSON, bypassing the configured signature policy. This allows a remote attacker to submit unauthorized claims, leading to a compromise of data integrity within the OpenID Connect (OIDC) authorization flow. While a redirect URI allowlist acts as a compensating control, this vulnerability violates OIDC Core and Financial-grade API (FAPI) signing requirements.

CVSS3: 5.9
nvd
2 месяца назад

A flaw was found in Keycloak. When a JSON Web Encryption (JWE) encrypted request object is submitted, Keycloak may incorrectly process unsigned claims if the decrypted content is raw JSON, bypassing the configured signature policy. This allows a remote attacker to submit unauthorized claims, leading to a compromise of data integrity within the OpenID Connect (OIDC) authorization flow. While a redirect URI allowlist acts as a compensating control, this vulnerability violates OIDC Core and Financial-grade API (FAPI) signing requirements.

CVSS3: 5.9
debian
2 месяца назад

A flaw was found in Keycloak. When a JSON Web Encryption (JWE) encrypt ...

EPSS

Процентиль: 2%
0.0012
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-347