Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-9793

Опубликовано: 28 мая 2026
Источник: nvd
CVSS3: 5.9
CVSS3: 7.5
EPSS Низкий

Описание

A flaw was found in Keycloak. When a JSON Web Encryption (JWE) encrypted request object is submitted, Keycloak may incorrectly process unsigned claims if the decrypted content is raw JSON, bypassing the configured signature policy. This allows a remote attacker to submit unauthorized claims, leading to a compromise of data integrity within the OpenID Connect (OIDC) authorization flow. While a redirect URI allowlist acts as a compensating control, this vulnerability violates OIDC Core and Financial-grade API (FAPI) signing requirements.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:redhat:build_of_keycloak:-:*:*:*:-:*:*:*

EPSS

Процентиль: 2%
0.0012
Низкий

5.9 Medium

CVSS3

7.5 High

CVSS3

Дефекты

CWE-347

Связанные уязвимости

CVSS3: 5.9
redhat
2 месяца назад

A flaw was found in Keycloak. When a JSON Web Encryption (JWE) encrypted request object is submitted, Keycloak may incorrectly process unsigned claims if the decrypted content is raw JSON, bypassing the configured signature policy. This allows a remote attacker to submit unauthorized claims, leading to a compromise of data integrity within the OpenID Connect (OIDC) authorization flow. While a redirect URI allowlist acts as a compensating control, this vulnerability violates OIDC Core and Financial-grade API (FAPI) signing requirements.

CVSS3: 5.9
debian
2 месяца назад

A flaw was found in Keycloak. When a JSON Web Encryption (JWE) encrypt ...

CVSS3: 5.9
github
2 месяца назад

Keycloak has an Improper Verification of Cryptographic Signature issue

EPSS

Процентиль: 2%
0.0012
Низкий

5.9 Medium

CVSS3

7.5 High

CVSS3

Дефекты

CWE-347